GoHarbor · Authentication Profile
Goharbor Authentication
Authentication
The Harbor v2.0 API accepts exactly one credential presentation — HTTP Basic — but four different principals can sit behind it, and which ones exist is decided by the operator's chosen authentication mode. That distinction is the thing to get right: OIDC and LDAP configure who can LOG IN; API callers still send Basic credentials, and for an OIDC instance the password is a Harbor-issued CLI secret, not the IdP password.
GoHarbor secures its APIs with http across 2 declared security schemes, as derived from its OpenAPI definitions.
Container RegistryContainersArtifactsVulnerability ScanningSupply Chain SecurityOCIOpen SourceKubernetesDevOpsReplication
Methods: http
Schemes: 2
OAuth flows:
API key in:
Security Schemes
basicAuth http
BearerAuth http
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.