Foreign Agricultural Service · Authentication Profile

Foreign Agricultural Service Authentication

Authentication

Foreign Agricultural Service secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.

AgricultureFederal GovernmentTradeOpen DataCommoditiesExportGovernment
Methods: apiKey Schemes: 1 OAuth flows: API key in: header

Security Schemes

apiKey apiKey
· in: header (API_KEY)

Source

Authentication Profile

Raw ↑
generated: '2026-09-10'
method: searched
source: >-
  openapi/_original/foreign-agricultural-service-fas-open-data-swagger.json (the provider's
  live Swagger 2.0 at https://apps.fas.usda.gov/opendata/swagger/docs/v1), the OpendataWeb
  portal signup flow, and live probes on 2026-09-10
docs: https://apps.fas.usda.gov/opendatawebv2/#/signup
note: >-
  Upgraded from derived to searched: the derived pass read the scheme out of the refined
  OpenAPIs, this one adds the provider's own contract wording, the issuance flow read out of
  the portal bundle, and the observed failure behaviour. FAS publishes no prose authentication
  guide — the Swagger UI and the signup form are the whole of it.
summary:
  types:
    - apiKey
  api_key_in:
    - header
  oauth2_flows: []
  scopes: 0
  scopes_note: >-
    No OAuth, no scopes, no permissions model, so no scopes/ artifact is written. A key is
    all-or-nothing across all 35 operations and all three datasets — there is no way to issue
    a key limited to, say, PSD.
schemes:
  - name: apiKey
    type: apiKey
    in: header
    parameter: API_KEY
    description: 'API Key Authentication (verbatim from the contract''s securityDefinitions)'
    applied: >-
      globally — the contract declares a root-level `security` requirement naming this scheme,
      and every one of the 35 operations inherits it
    format: the raw key value, with no scheme prefix (not `Bearer`, not `ApiKey`)
    query_parameter_accepted: false
    query_parameter_note: >-
      The contract declares `in: header` only. Keeping the credential out of the URL is the
      safer of the two designs — it stays out of access logs, Referer headers and browser
      history — and it is worth crediting FAS for, because plenty of open-data APIs do the
      opposite.
    sources:
      - openapi/_original/foreign-agricultural-service-fas-open-data-swagger.json
      - openapi/foreign-agricultural-service-esr-api-openapi.yml
      - openapi/foreign-agricultural-service-gats-api-openapi.yml
      - openapi/foreign-agricultural-service-psd-api-openapi.yml
issuance:
  cost: free
  onboarding: self-serve
  signup_url: https://apps.fas.usda.gov/opendatawebv2/#/signup
  issuer: api.data.gov
  mechanism: >-
    The FAS portal embeds the api.data.gov signup widget — the Angular bundle at
    apps.fas.usda.gov/opendatawebV2/main.*.js loads
    https://api.data.gov/static/javascripts/signup_embed.js — so the key is minted by
    api.data.gov and delivered by email, then presented to the FAS API directly.
  gateway_note: >-
    Precise distinction, because it changes what a consumer should expect: api.data.gov
    ISSUES the key but does NOT proxy this API. apps.fas.usda.gov validates the key itself,
    its responses carry none of the api.data.gov gateway headers, and its error body is FAS's
    own. So api.data.gov's published rate limits and X-RateLimit headers do not apply here.
  approval: automatic — no application, no review, no terms acceptance beyond the signup form
  key_rotation:
    documented: false
    note: no rotation, revocation or expiry policy is published, and the portal exposes no key-management screen
observed_failure_modes:
  probed: '2026-09-10'
  probed_endpoint: https://apps.fas.usda.gov/OpenData/api/esr/regions
  not_probed: >-
    The authenticated success path was not exercised. API Evangelist holds no FAS API key and
    does not obtain credentials for profiled providers.
  modes:
  - condition: no API_KEY header
    status: 403
    body: '"Bad API Key"'
    note: bare JSON string, not an object — a client parsing it as JSON gets a string, not a dict
  - condition: malformed API_KEY value
    status: 500
    body: '{"message":"An error has occurred."}'
    note: >-
      A real defect. An invalid credential should be 401 or 403; returning 500 tells retry
      libraries to treat a permanent auth failure as a transient server error and retry it.
      Full write-up in errors/foreign-agricultural-service-problem-types.yml.
transport:
  https_only: true
  hsts: 'max-age=31536000; includeSubdomains; preload (observed on API responses)'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/foreign-agricultural-service-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.