Florist One · Authentication Profile

Florist One Authentication

Authentication

Florist One secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

DeliveryE-CommerceFloristsFlowersGifts
Methods: http Schemes: 1 OAuth flows: API key in:

Security Schemes

basicAuth http
scheme: basic

Source

Authentication Profile

Raw ↑
generated: '2026-09-10'
method: searched
source: >-
  https://www.floristone.com/api/technical-information/,
  https://www.floristone.com/api/print_api_legal/,
  https://github.com/fhwsolutions/FloristOne_API (Florist One's published sample code),
  live probe of https://www.floristone.com/api/rest/flowershop/getproducts,
  openapi/_original/florist-one-openapi.yml
docs: https://www.floristone.com/api/technical-information/
docs_note: >-
  The auth documentation page is itself gated — https://www.floristone.com/api/technical-information/
  returns 200 but renders a login form asking for an API Key and Password. The credential
  model below was reconstructed from Florist One's own public sample code and one live
  probe, not from a published auth reference.
summary:
  types:
    - http
  api_key_in: []
  oauth2_flows: []
  credential_issuance: manual, after signup at https://www.floristone.com/api/api-signup/
schemes:
  - name: basicAuth
    type: http
    scheme: basic
    description: HTTP Basic auth with API Key as username and assigned password
    sources:
      - openapi/_original/florist-one-openapi.yml
      - openapi/florist-one-flowershop-api-openapi.yml
      - openapi/florist-one-giftbaskets-api-openapi.yml
      - openapi/florist-one-shoppingcart-api-openapi.yml
      - openapi/florist-one-affiliate-api-openapi.yml
credential:
  username: API Key (a numeric key issued by Florist One)
  password: assigned password
  issuance: >-
    Issued on signup at https://www.floristone.com/api/api-signup/. Accepting the API
    Agreement is a condition of use — "By clicking the Accept button for this Agreement
    and/or using an API key issued by Provider, you confirm your acceptance".
  rotation: not documented
  revocation: >-
    Florist One may suspend or terminate API access for material breach, illegal or
    fraudulent activity, or termination of a subcontractor's services (API Agreement,
    section 5.2.2). No self-service key rotation or revocation is documented.
  multi_key_requirement: >-
    An integrator selling into both the United States and Canada must hold TWO API keys and
    swap them by order destination, because orders to the US are charged in USD and orders
    to Canada in CAD. Published in https://www.floristone.com/api/flowers-api-faq/.
wire_format:
  header: Authorization
  observed_form: 'Authorization: <base64(apikey:password)>'
  rfc7617_conformant: false
  deviation_note: >-
    Every published sample — php/flowershop/placeorder.php, php/shoppingcart/*.php,
    php/affiliate/legalagreement.php and the ColdFusion equivalents — builds the header as
    base64_encode("{$username}:{$password}") and sends it with NO `Basic ` scheme prefix.
    RFC 7617 requires the scheme token. Whether the server accepts the RFC form as well is
    not documented anywhere public, so an integrator using a standard HTTP client's
    basic-auth helper cannot tell from the documentation whether it will work.
  transport: HTTPS only
unauthenticated_behavior:
  fetched: '2026-09-10'
  url: https://www.floristone.com/api/rest/flowershop/getproducts?category=fx&count=2&start=1
  http_status: 403
  content_type: text/html
  body: >-
    Stock Microsoft IIS error page reading "403 - Forbidden: Access is denied."
  note: >-
    No WWW-Authenticate challenge is returned, which is a further deviation from HTTP Basic
    — a client is given no machine-readable indication of which scheme or realm to use. The
    error is untyped HTML. See errors/florist-one-problem-types.yml.
not_supported:
  oauth2: true
  openid_connect: true
  api_key_header: true
  mutual_tls: true
  scopes: >-
    No scope, permission, or role model exists. One credential grants the whole surface,
    including order placement. There is no read-only key, which means an agent given a key
    to browse products is also holding a key that can charge a card.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/florist-one-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.