Genialis · Authentication Profile

Genialis Authentication

Authentication

Genialis secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.

CompanyBioinformaticsPrecision MedicineGenomicsLife SciencesHealthcareMachine LearningArtificial IntelligenceMultiomicsOncologyData PlatformOpen Source
Methods: apiKey Schemes: 1 OAuth flows: API key in: cookie

Security Schemes

cookieAuth apiKey
· in: cookie (sessionid)

Source

Authentication Profile

Raw ↑
generated: '2026-08-21'
method: searched
source: >-
  openapi/genialis-base-openapi.yaml (securitySchemes + the /rest-auth and
  /saml-auth operations), https://docs.genialis.com/resdk/start.html (the documented
  login flow), and the OIDC discovery document at
  https://genialis.us.auth0.com/.well-known/openid-configuration probed 2026-08-21
docs: https://docs.genialis.com/resdk/start.html
api: Genialis Expressions API
base_url: https://app.genialis.com
summary:
  types:
  - apiKey
  api_key_in:
  - cookie
  bearer_token: false
  api_key_header: false
  oauth2_for_api: false
  scopes: false
  federated_login: true
  sso: saml
  anonymous_read: true
schemes:
- name: cookieAuth
  type: apiKey
  in: cookie
  parameter: sessionid
  sources:
  - openapi/genialis-base-openapi.yaml
  note: >-
    The only security scheme in the contract. Applied per-operation; there is no
    global `security` block. Several operations declare `[cookieAuth, {}]`, i.e.
    anonymous access is explicitly permitted.
anonymous_access:
  supported: true
  evidence:
  - request: GET https://app.genialis.com/api/data?limit=1
    status: 200
    note: 'returned {"count":29123,...} with no credentials'
  - request: GET https://app.genialis.com/api/collection?limit=1
    status: 200
    note: 'returned {"count":107,...}'
  - request: GET https://app.genialis.com/api/user
    status: 200
    note: 'returned [] — anonymous sees no users'
  scope: Public and community datasets only. Private objects require a session.
identity_provider:
  vendor: Auth0
  tenant: https://genialis.us.auth0.com/
  discovery: https://genialis.us.auth0.com/.well-known/openid-configuration
  discovery_status: 200
  saved: well-known/genialis-openid-configuration.json
  protocols: [OIDC, OAuth 2.0]
  pkce: S256
  id_token_algs: [RS256, HS256, PS256]
  idp_scopes: [openid, profile, email, offline_access, phone, address]
  important: >-
    These are the IdP's OIDC scopes, NOT API authorization scopes. The Genialis REST
    API does not accept an Auth0 access token — the browser flow terminates in a
    Django `sessionid` cookie, and that cookie is what the API reads. There is no
    scope model for API resources; authorization is per-object ACL (see
    data-model/genialis-data-model.yml, permissions_model).
  how_found: >-
    The restricted docs.genialis.com sections (supermodel, gpm, deploy, internal)
    302 to https://genialis.us.auth0.com/u/login.
flows:
- id: resdk-interactive
  documented: true
  docs: https://docs.genialis.com/resdk/start.html
  headless: false
  code: |
    import resdk
    res = resdk.Resolwe(url='https://app.genialis.com')
    res.login()          # performs interactive login in a web browser
    resdk.start_logging()
  note: >-
    The only flow Genialis documents. Quoted from the docs: "The `login()` call will
    perform interactive login in a web browser" and "If you omit the `login()` line
    you will be logged as anonymous user." An unattended agent cannot complete this
    without a human at a browser.
- id: rest-auth-session
  documented: false
  operations:
  - id: rest_auth_login_create
    method: POST
    path: /rest-auth/login/
    description: Attempt to perform automatic login.
  - id: rest_auth_logout_create
    method: POST
    path: /rest-auth/logout/
    description: Calls Django logout method and deletes the Token object assigned to the user.
  - id: rest_auth_user_retrieve
    method: GET
    path: /rest-auth/user/
    description: Reads and updates UserModel fields.
    use: cheapest way to verify a live session
  - id: rest_auth_password_change_create
    method: POST
    path: /rest-auth/password/change/
  - id: rest_auth_password_reset_create
    method: POST
    path: /rest-auth/password/reset/
  - id: rest_auth_password_reset_confirm_create
    method: POST
    path: /rest-auth/password/reset/confirm/
  gap: >-
    django-rest-auth endpoints are present in the contract but declare NO request
    body schema and NO error responses, so the credential field names are not
    discoverable from the spec and no failure mode is described.
- id: saml-sso
  documented: false
  operations:
  - id: saml_auth_api_login_create
    method: POST
    path: /saml-auth/api-login/
    description: Attempt to perform automatic login.
  - id: saml_auth_remote_login_auth_id_retrieve
    method: GET
    path: /saml-auth/remote-login/auth-id/
    description: Generate a cryptographically secure auth_id token.
  - id: saml_auth_remote_login_poll_retrieve
    method: GET
    path: /saml-auth/remote-login/poll/
    description: Poll the redis server for authentication data.
  note: >-
    A device-style pairing flow — mint an auth_id, send the user to the IdP, poll
    until the session materialises. This is the mechanism behind resdk's browser
    login and it is the enterprise SSO surface.
authorization:
  model: per-object ACL
  endpoints:
  - /api/data/{id}/permissions
  - /api/collection/{id}/permissions
  - /api/sample/{id}/permissions
  - /api/process/{id}/permissions
  - /api/descriptorschema/{id}/permissions
  principals: [user, group, public]
  scopes: none
outbound_oauth:
  note: >-
    Genialis acts as an OAuth CLIENT against Illumina BaseSpace:
    /api/basespace/oauth_browse_url and /api/basespace/oauth_read_projects_url return
    URLs for requesting BaseSpace permissions. This is not inbound API auth.
gaps:
- No machine-to-machine credential. There is no API key, no bearer token and no client_credentials path to the REST API — every documented route to a session requires a human at a browser.
- No 401/403 response is documented on any of the 254 operations.
- The /rest-auth/* operations have no request schema, so the login payload cannot be built from the contract.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/genialis-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.