Flagsmith · Authentication Profile
Flagsmith Authentication
Authentication
Flagsmith secures its APIs with apiKey, http, and oauth2 across 7 declared security schemes, as derived from its OpenAPI definitions.
Feature FlagsRemote ConfigRelease ManagementA/B TestingExperimentationSegmentationDeveloper ToolsDevOpsOpen SourceSoftware-as-a-ServiceMCPAgent Ready
Methods: apiKey, http, oauth2
Schemes: 7
OAuth flows:
API key in: header
Security Schemes
Environment API Key apiKey
· in: header (X-Environment-Key)
Master API Key apiKey
· in: header (Authorization)
tokenAuth apiKey
· in: header (Authorization)
Cohort Sync Key http
scheme: bearer
Cohort Sync Key (Basic) http
scheme: basic
basicAuth http
scheme: basic
OAuth 2.0 oauth2
Source
Authentication Profile
generated: '2026-09-17'
method: searched
source: >-
https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/management-api/authentication,
https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/flags-api/authentication,
https://docs.flagsmith.com/integrating-with-flagsmith/mcp-server,
https://api.flagsmith.com/.well-known/oauth-authorization-server (200), and
openapi/_original/flagsmith-api-openapi.json#/components/securitySchemes (six declared schemes).
docs: https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/
supersedes: >-
The 2026-09-17 derived pass, which read only the nine split specs in openapi/ and saw a single
apiKey scheme. The harvested first-party contract declares six, and OAuth 2.0 is declared in none
of them — it is only visible in the .well-known metadata.
summary:
types: [apiKey, http, oauth2]
api_key_in: [header]
oauth2: true
mtls: false
openid_connect: false
key_insight: >-
Two API surfaces, two different keys, and they are not interchangeable — this is the thing to get
right first. The SDK/Flags API on edge.api.flagsmith.com takes a NON-SECRET environment key in
X-Environment-Key and is safe in client-side code. The Management API on api.flagsmith.com takes a
SECRET organisation key in Authorization with a mandatory `Api-Key ` prefix and must never reach a
browser. A third path, OAuth 2.0, exists only for the MCP server and the Management API and is
absent from the OpenAPI entirely.
schemes:
- name: Environment API Key
type: apiKey
in: header
parameter: X-Environment-Key
secret: false
surface: SDK / Flags API (https://edge.api.flagsmith.com)
description: >-
Per-environment client-side key, found in the dashboard under the project's Environments tab.
Safe to ship in client-side code by design. SDKs set the header for you on initialisation; direct
HTTP callers must set it on every request.
docs: https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/flags-api/authentication
sources: [openapi/_original/flagsmith-api-openapi.json]
- name: Master API Key
type: apiKey
in: header
parameter: Authorization
value_format: 'Api-Key <key>'
secret: true
surface: Management API (https://api.flagsmith.com/api/v1)
description: >-
Organisation-level secret token. The `Api-Key ` prefix is required — the header must read
`Api-Key ser.abc123…`, not the bare key. Requests act with the permissions of the key's user, so
administrator privileges are not required and RBAC still applies.
docs: https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/management-api/authentication
sources: [openapi/_original/flagsmith-api-openapi.json]
- name: tokenAuth
type: apiKey
in: header
parameter: Authorization
value_format: 'Token <key>'
secret: true
surface: Management API
description: Django REST Framework token authentication, used by session/user tokens rather than organisation keys.
sources: [openapi/_original/flagsmith-api-openapi.json]
- name: Cohort Sync Key
type: http
scheme: bearer
secret: true
surface: Cohort sync webhooks
description: For cohort-sync endpoints called by an external cohort source, such as Amplitude.
sources: [openapi/_original/flagsmith-api-openapi.json]
- name: Cohort Sync Key (Basic)
type: http
scheme: basic
secret: true
surface: Cohort sync webhooks
description: >-
For cohort sources that can only send Basic credentials, such as Mixpanel. The key is the
password; the username is ignored.
sources: [openapi/_original/flagsmith-api-openapi.json]
- name: basicAuth
type: http
scheme: basic
secret: true
surface: Management API (legacy/internal)
sources: [openapi/_original/flagsmith-api-openapi.json]
- name: OAuth 2.0
type: oauth2
flow: authorization_code
pkce: S256
scopes: [mcp, admin-api]
surface: MCP server (https://mcp.flagsmith.com) and Management API
authorization_server: https://api.flagsmith.com
discovery: https://api.flagsmith.com/.well-known/oauth-authorization-server
dynamic_client_registration: https://api.flagsmith.com/o/register/
description: >-
Not declared anywhere in the OpenAPI — discoverable only from the RFC 8414 document on the API
host and the RFC 9728 document on the MCP host. Interactive MCP clients use it to avoid handling
an API key at all.
docs: https://docs.flagsmith.com/integrating-with-flagsmith/mcp-server
see: scopes/flagsmith-scopes.yml
sso:
note: >-
End-user sign-in to the Flagsmith dashboard (not API authentication) supports SAML 2.0, Okta,
ADFS, LDAP, Google and GitHub OAuth, plus 2FA. SAML, LDAP and SCIM provisioning are Enterprise;
2FA is available from the Start-Up plan.
docs: https://docs.flagsmith.com/administration-and-security/access-control/
standards: [SAML 2.0, LDAP, SCIM 2.0]
authorization:
model: RBAC
note: >-
Roles, permission groups and per-project/per-environment permissions gate every Management API
call; custom roles are Enterprise. 34 operations in the contract are tagged Permissions.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/flagsmith-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.