Flanks · Authentication Profile

Flanks Authentication

Authentication

Flanks secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).

CompanyWealth ManagementFinancial DataData AggregationFintechInvestmentsOpen BankingAPIs
Methods: oauth2 Schemes: 1 OAuth flows: clientCredentials API key in:

Security Schemes

OAuth2ClientCredentials oauth2

Source

Authentication Profile

flanks-authentication.yml Raw ↑
generated: '2026-07-19'
method: searched
source: https://docs.flanks.io/pages/flanks-apis/authentication/
docs: https://docs.flanks.io/pages/flanks-apis/authentication/
summary:
  types: [oauth2]
  oauth2_flows: [clientCredentials]
  bearer: true
schemes:
  - name: OAuth2ClientCredentials
    type: oauth2
    flow: clientCredentials
    token_endpoint: https://api.flanks.io/v0/token
    grant_type: client_credentials
    request:
      method: POST
      content_type: application/json
      parameters:
        - client_id
        - client_secret
        - grant_type
    response:
      access_token: string
      token_type: Bearer
      expires_in: 3600
      scope: space-delimited list of scopes
    usage: 'Every request carries header Authorization: Bearer <access_token>'
notes: >-
  All Flanks API calls must be authenticated. Obtain a bearer access token from
  the token endpoint using the OAuth2 client-credentials grant, then send it in
  the Authorization header. Access tokens expire after 3600 seconds. The hosted
  Flanks MCP server uses a separate OAuth2 authorization server
  (https://flanks-mcp.flanks.io) supporting authorization_code, refresh_token,
  and client_credentials with PKCE (S256).