Freddie Mac · Authentication Profile
Freddie Mac Authentication
Authentication
Freddie Mac secures its APIs with http across 2 declared security schemes, as derived from its OpenAPI definitions.
Freddie MacHousingMortgageLendingServicingOriginationSecondary MarketMISMOFortune 100Government-Sponsored Enterprise
Methods: http
Schemes: 2
OAuth flows:
API key in:
Security Schemes
bearerAuth http
scheme: bearer
basicAuth http
scheme: basic
Source
Authentication Profile
generated: '2026-09-10'
method: searched
source: 20 first-party OpenAPI contracts harvested from the Freddie Mac Developer Portal public API catalog,
plus the portal's own Getting Started page and the OAuth error taxonomy the specs publish in their 401
response descriptions.
summary:
types:
- http
schemes:
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: token
sources:
- openapi/freddie-mac-affordable-check-openapi.json
- openapi/freddie-mac-beyond-ace-openapi.yaml
- openapi/freddie-mac-cash-settlement-purchase-statement-openapi.json
- openapi/freddie-mac-current-mortgage-snapshot-openapi.json
- openapi/freddie-mac-data-share-bid-tape-openapi.json
- openapi/freddie-mac-data-share-openapi.json
- openapi/freddie-mac-guarantor-settlement-purchase-statement-openapi.json
- openapi/freddie-mac-income-limits-openapi.json
- openapi/freddie-mac-loan-closing-advisor-loan-submission-openapi.yaml
- openapi/freddie-mac-loan-import-openapi.json
- openapi/freddie-mac-loan-look-up-openapi.json
- openapi/freddie-mac-property-insights-openapi.json
- openapi/freddie-mac-resolve-liquidation-openapi.json
- openapi/freddie-mac-resolve-retention-openapi.json
- openapi/freddie-mac-resolve-valuation-pricing-openapi.json
- openapi/freddie-mac-resolve-workout-options-openapi.json
- name: basicAuth
type: http
scheme: basic
sources:
- openapi/freddie-mac-cash-committing-openapi.json
- openapi/freddie-mac-cash-pricing-openapi.json
- openapi/freddie-mac-guarantor-committing-openapi.json
- openapi/freddie-mac-guarantor-pricing-openapi.json
docs: https://sf.freddiemac.com/tools-learning/apis/getting-started-with-apis
profile:
primary: OAuth 2.0 bearer token issued by the Freddie Mac Apigee gateway
secondary: HTTP Basic on the four Loan Selling Advisor pricing/committing services (lassvcs-uat.fmrei.com/ESO/rest)
credential_issuance: System-to-system API credentials are issued by a Freddie Mac representative to
an organisation with counterparty (Seller/Servicer) or approved technology-partner status; there is
no self-service signup. A Developer Administrator then creates an app in the Developer Portal and
requests promotion to production.
token_endpoint_published: false
token_endpoint_note: 'No OAuth token endpoint, authorization-server metadata document or /.well-known/oauth-authorization-server
is published anonymously. Probed 2026-09-10: api.freddiemac.com and api-test.freddiemac.com both 404
that path; developer.freddiemac.com 401s it. The token URL is documented only inside the authenticated
portal.'
grant_evidence: 'The 401 response descriptions in every gateway-fronted spec enumerate an OAuth 2.0
credential lifecycle: 401.001 invalid access token, 401.002 access token expired, 401.003 API product
mismatch for token, 401.004 invalid API key (client ID), 401.005 invalid API key for resource, 401.006
insufficient scope for application, 401.007 invalid username/password combination, 401.008 invalid
refresh token, 401.009 invalid client secret, 401.010 refresh token expired. Client ID + client secret
+ refresh tokens + per-product scope is an Apigee OAuth 2.0 deployment; the username/password code
additionally implies a resource-owner-password grant.'
scopes_published: false
scopes_note: Scope is enforced (401.006 'Insufficient scope for Application' and 401.003 'API Product
mismatch for token') but no scope names are published in any spec or on any public page, so no scopes/
artifact was written rather than an invented one.
vendor_headers:
- name: X-Lender-Id
apis:
- Beyond ACE
- Property Insights
note: lender identifier, sent on 11 operations
- name: X-Amc-Id
apis:
- Beyond ACE
note: appraisal management company identifier
- name: X-LenderLoan-Id
apis:
- Beyond ACE
note: lender loan identifier
- name: X-CSS-VENDOR-IDENTIFIER / -NAME / -SOFTWARE / -SOFTWARE-VERSION
apis:
- Cash Settlement Purchase Statement
note: software-provider attribution headers required alongside the bearer token
- name: X-LIS-VENDOR-IDENTIFIER / -NAME / -SOFTWARE / -SOFTWARE-VERSION
apis:
- Loan Import
note: software-provider attribution headers required alongside the bearer token
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/freddie-mac-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.