Heathrow Airport Authentication
Heathrow runs a two-layer authentication model, and both layers are closed to anonymous callers. Human access to the developer portal is federated to Microsoft Entra ID (Azure Active Directory) and only issued after a manual enrolment conversation with Heathrow. Machine access to the runtime gateway at api.heathrow.com is gated by mutual TLS - the Azure Application Gateway terminates every anonymous request with "400 No required SSL certificate was sent" before routing, so a client certificate issued by Heathrow is a precondition to reaching any operation. No OpenAPI is published, so no securityScheme could be derived; this profile is taken from the provider's own public prose plus observed gateway behaviour.
Heathrow Airport secures its APIs with mutualTLS and federated-sso across 2 declared security schemes, as derived from its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.