Gamma.app · Authentication Profile

Gammaapp Authentication

Authentication

Gamma.app secures its APIs with apiKey and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyArtificial IntelligencePresentationsDocumentsContent GenerationGenerative AIProductivityMCPWebsitesSocial Media
Methods: apiKey, oauth2 Schemes: 2 OAuth flows: authorizationCode API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header ()
OAuth2 oauth2
scheme: bearer

Source

Authentication Profile

gammaapp-authentication.yml Raw ↑
generated: '2026-07-19'
method: searched
source: >-
  https://developers.gamma.app/get-started/understanding-the-api-options ,
  https://developers.gamma.app/reference/error-codes ,
  https://developers.gamma.app/mcp/mcp-tools-reference
summary:
  types: [apiKey, oauth2]
  api_key_in: [header]
  oauth2_flows: [authorizationCode]
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter_name: X-API-KEY
  key_prefix: sk-gamma-
  surface: REST API (https://public-api.gamma.app/v1.0)
  plans: [Pro, Ultra, Teams, Business]
  provisioning: https://gamma.app/settings/api-keys
  notes: >-
    All REST requests require an API key in the case-sensitive X-API-KEY header.
    Keys start with sk-gamma-. Invalid/missing keys return 401 "Invalid API key".
- name: OAuth2
  type: oauth2
  scheme: bearer
  surface: Gamma MCP server (https://mcp.gamma.app/mcp)
  authorization_server: https://auth.gamma.app
  protected_resource_metadata: https://mcp.gamma.app/.well-known/oauth-protected-resource
  dynamic_client_registration: true
  specs: [RFC 9728, RFC 7591]
  scopes: [generate, 'gamma:read']
  notes: >-
    The hosted MCP server (and the ChatGPT/Claude connectors it powers) uses
    OAuth 2.0 Bearer tokens with Dynamic Client Registration. Available on all
    plans.