Grubhub · Authentication Profile
Grubhub Authentication
Authentication
Grubhub secures its APIs with apiKey and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorization_code flow(s).
Food DeliveryRestaurantMarketplaceOnline OrderingPoint-of-SaleLogisticsLast Mile DeliveryMenu ManagementHospitalityLocal CommerceDelivery
Methods: apiKey, oauth2
Schemes: 2
OAuth flows: authorization_code
API key in: header
Security Schemes
partnerKey apiKey
· in: header (X-GH-PARTNER-KEY)
grubhubOAuth oauth2
Source
Authentication Profile
generated: '2026-09-17'
method: searched
source: >-
openapi/_harvested/*.json (Grubhub's own twelve OpenAPI documents, fetched 2026-09-17 from
https://developer.grubhub.com/resource/partner-docs/api-docs/) plus the live RFC 8414 document
at https://api-third-party-gtm.grubhub.com/.well-known/oauth-authorization-server
note: >-
Grubhub's partner OpenAPI documents declare NO components.securitySchemes. Authentication is
expressed instead as an explicit X-GH-PARTNER-KEY request header on 31 operations across the
Connect (DaaS), Menu, Orders, Onboarding and Reporting documents, and the Onboarding document
states in prose that merchant association/deactivation is validated "using Oauth2". The
OAuth authorization server is real and discoverable: it publishes RFC 8414 metadata
anonymously on both partner hosts.
summary:
types:
- apiKey
- oauth2
api_key_in:
- header
oauth2_flows:
- authorization_code
securityschemes_declared_in_spec: false
mfa_or_signing: unknown
schemes:
- name: partnerKey
type: apiKey
in: header
parameter: X-GH-PARTNER-KEY
format: uuid
required_in_spec: mixed
description: >-
Partner identity key issued by Grubhub during partner onboarding. Declared as a header
parameter on 31 operations. It is required:true on the eight Onboarding operations (schema
type string, format uuid) and required:false on the Connect (DaaS), Orders, Menu and
Reporting operations that declare it.
operations: 31
evidence:
- openapi/grubhub-connect-endpoints-openapi.yml
- openapi/grubhub-onboarding-openapi.yml
- openapi/grubhub-orders-openapi.yml
- openapi/grubhub-menu-openapi.yml
- openapi/grubhub-reporting-endpoints-openapi.yml
- name: grubhubOAuth
type: oauth2
description: >-
Grubhub runs an RFC 8414 OAuth 2.0 authorization server whose metadata is served
anonymously from the partner API hosts. It advertises dynamic client registration
(RFC 7591), PKCE with S256 and plain, client_secret_post token endpoint authentication,
and the scopes openid and diner.
discovery: well-known/grubhub-oauth-authorization-server.json
issuer: https://api-gtm.grubhub.com
authorization_endpoint: https://api-gtm.grubhub.com/oauth2/authorize
token_endpoint: https://api-gtm.grubhub.com/oauth2/token
registration_endpoint: https://api-gtm.grubhub.com/oauth/register
token_endpoint_auth_methods_supported:
- client_secret_post
code_challenge_methods_supported:
- S256
- plain
scopes_supported:
- openid
- diner
service_documentation: https://developer.grubhub.com
evidence:
- url: https://api-third-party-gtm.grubhub.com/.well-known/oauth-authorization-server
status: 200
fetched: '2026-09-17'
environments:
- name: production
base_url: https://api-third-party-gtm.grubhub.com
issuer: https://api-gtm.grubhub.com
- name: preproduction
base_url: https://api-third-party-gtm-pp.grubhub.com
issuer: https://api-order-taking-pp.grubhub.com
evidence:
- url: https://api-third-party-gtm-pp.grubhub.com/.well-known/oauth-authorization-server
status: 200
fetched: '2026-09-17'
gaps:
- No securitySchemes block in any published OpenAPI document, so no operation carries a machine-readable
security requirement; a client cannot tell from the contract which credential an operation needs.
- No /.well-known/openid-configuration and no jwks_uri published on any host probed.
- No /.well-known/oauth-protected-resource, so the resource-server side of RFC 9728 is undiscoverable.
- The prose auth guide lives on developer.grubhub.com, which renders client-side from Contentful and
is not machine-readable.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/grubhub-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.