Emboss · Authentication Profile
Getemboss Ai Authentication
Authentication
Emboss secures its APIs with http, oauth2, and payment across 6 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
PDFFormsDocument ProcessingForm FillingFaxData ExtractionAgent-NativeMCPA2Ax402pay-per-callGovernment FormsCompany
Methods: http, oauth2, payment
Schemes: 6
OAuth flows: authorizationCode
API key in: header
Security Schemes
bearer http
scheme: bearer
oauth2 oauth2
· flows: authorizationCode
payment-mpp payment
scheme: Authorization: Payment
payment-x402 payment
scheme: x402 payment header carrying a signed EIP-3009 TransferWithAuthorization
artifact_token capability-token
status_url_token capability-token
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/getemboss-ai-account-openapi.yml and openapi/getemboss-ai-pay-per-call-openapi.yml (derived baseline by derive-authentication.py) upgraded from https://getemboss.ai/docs/authentication, /docs/mcp-tools, /docs/a2a, /docs/pay-per-call/mpp, /docs/pay-per-call/x402, /docs/artifacts and the live discovery documents under well-known/
docs: https://getemboss.ai/docs/authentication
summary:
types: [http, oauth2, payment]
api_key_in: [header]
oauth2_flows: [authorizationCode]
note: >-
Four ways in, matched to four doors. (1) Bearer API key on the account REST API, A2A and (as a fallback) MCP.
(2) OAuth 2.1 authorization code + PKCE with dynamic client registration on MCP and A2A. (3) Machine payment
in place of identity on the anonymous pay door — an MPP "Authorization: Payment" credential or an x402
EIP-3009 authorization answering a 402. (4) artifact_token as a capability token that lets an anonymous
caller reuse a file it paid for. GET /health and GET /library need nothing.
schemes:
- name: bearer
type: http
scheme: bearer
bearerFormat: Emboss API key (sk_...)
header: 'Authorization: Bearer sk_live_...'
key_prefix: sk_live_
description: An Emboss API key. See https://getemboss.ai/docs/authentication.
sources: [openapi/getemboss-ai-account-openapi.yml, a2a/getemboss-ai-agent-card.json]
issuance: Created, rotated, disabled and revoked in the dashboard (Dashboard > Account > API keys); also the REST operations create_key_keys_post / list_keys_keys_get / patch_key_keys__key_id__patch / delete_key_keys__key_id__delete.
storage: Keys are stored hashed, never in plain text (https://getemboss.ai/security).
scope: Owner-scoped — a key can only read and mutate the forms and sessions created with that same key; a request for another owner's resource returns 404, not 403, so existence is not leaked across accounts.
lifecycle:
states: [active, disabled, revoked]
disabled: Requests return 401; reversible — re-enable in the dashboard.
revoked: Requests return 401; permanent — issue a new key.
rotation: Create the new key, move traffic, then revoke the old one.
rejections:
401: No Authorization header or a malformed one; a well-formed but unknown, disabled or revoked key.
404: A valid key reaching a resource it does not own.
402: Over the monthly free tier with no card on file.
429: Over the request rate limit.
test_mode: none — sk_live_ is the only prefix; see sandbox/getemboss-ai-sandbox.yml
- name: oauth2
type: oauth2
issuer: https://api.getemboss.ai
flows:
- flow: authorizationCode
authorizationUrl: https://api.getemboss.ai/oauth/authorize
tokenUrl: https://api.getemboss.ai/oauth/token
scopes: 2
pkce: S256
grant_types: [authorization_code, refresh_token]
registration_endpoint: https://api.getemboss.ai/oauth/register
revocation_endpoint: https://api.getemboss.ai/oauth/revoke
token_endpoint_auth_methods: [none, client_secret_post]
client_id_metadata_document_supported: true
description: Sign in with your Emboss account. See https://getemboss.ai/docs/authentication.
sources: [openapi/getemboss-ai-account-openapi.yml, well-known/getemboss-ai-oauth-authorization-server.json, well-known/getemboss-ai-oauth-protected-resource-mcp.json, a2a/getemboss-ai-agent-card.json]
used_by: [MCP (https://api.getemboss.ai/mcp — 401 challenge carries resource_metadata), A2A (card securitySchemes.oauth2), account API (spec global security)]
discovery: RFC 8414 metadata at https://api.getemboss.ai/.well-known/oauth-authorization-server; RFC 9728 metadata at https://api.getemboss.ai/.well-known/oauth-protected-resource/mcp
consent: Dashboard shows pending consents and granted apps (admin_oauth_* operations); users disconnect under Dashboard > Account > Connected apps.
detail: scopes/getemboss-ai-scopes.yml
- name: payment-mpp
type: payment
scheme: 'Authorization: Payment <credential>'
challenge: '402 with WWW-Authenticate: Payment (one challenge per method: tempo USDC.e at the exact price; stripe card via Shared Payment Tokens with a 0.50 USD minimum)'
receipt: Payment-Receipt response header on the 202
applies_to: https://api.getemboss.ai/pay/* (openapi/getemboss-ai-pay-per-call-openapi.yml, x-payment-info.protocols[].mpp)
docs: https://getemboss.ai/docs/pay-per-call/mpp
note: An Authorization header that does not use the Payment scheme is answered with a fresh 402 rather than a 400.
- name: payment-x402
type: payment
scheme: x402 payment header carrying a signed EIP-3009 TransferWithAuthorization
challenge: 'the same 402 carries a PAYMENT-REQUIRED header; accepts USDC on Base (eip155:8453) first, then one gasless GatewayWalletBatched entry per chain Circle Gateway supports'
applies_to: [https://api.getemboss.ai/pay/*, A2A tasks via the a2a-x402 extension (TASK_STATE_INPUT_REQUIRED with x402.payment.required)]
docs: https://getemboss.ai/docs/pay-per-call/x402
note: Quotes expire after 24 hours; on A2A a failed attempt consumes the quote nonce, on the pay door a fresh 402 is issued.
- name: artifact_token
type: capability-token
location: request body, next to artifact_id (per source entry in sources[])
description: Issued to anonymous pay-door callers with each result; proves ownership of an artifact so it can be reused in a later paid operation or a free utility without an account.
docs: https://getemboss.ai/docs/artifacts
sources: [openapi/getemboss-ai-pay-per-call-openapi.yml (202 response artifact_token)]
- name: status_url_token
type: capability-token
location: query parameter token on GET /pay/jobs/{job_id}
description: HMAC(job_id, server secret) minted in the 202; lets an anonymous payer poll a job with no account.
sources: [openapi/getemboss-ai-account-openapi.yml pay_job_status_pay_jobs__job_id__get description]
public_endpoints:
- GET /health
- GET /library
- GET /pricing
- POST /pay/quote
- GET /.well-known/* discovery documents
spec_gap: >-
The account spec declares bearer + oauth2 globally but the Idempotency-Key header, the payment schemes and the
artifact_token are documented only in prose; the pay spec declares security [] on each operation and expresses
payment through x-payment-info rather than a securityScheme.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/getemboss-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.