High Performance Software Foundation · Authentication Profile

Hpsf Authentication

Authentication

High Performance Software Foundation secures its APIs with none and http across 2 declared security schemes, as derived from its OpenAPI definitions.

HPCLinux FoundationOpen SourceScientific ComputingFoundationsSupercomputingOpen GovernanceEventConferencesResearch ComputingNon-Profit
Methods: none, http Schemes: 2 OAuth flows: API key in:

Security Schemes

Anonymous none
BasicAuth http
scheme: basic

Source

Authentication Profile

hpsf-authentication.yml Raw ↑
generated: '2026-09-13'
method: searched
source: >-
  https://hpsf.io/wp-json/ (the route index, which declares the Application Passwords authorization
  endpoint), the BasicAuth securityScheme in the tec/v1 contract at https://hpsf.io/wp-json/tec/v1/docs,
  and live anonymous calls against every namespace on 2026-09-13.
name: HPSF authentication
summary:
  types:
  - none
  - http
  anonymous_read: true
  api_keys: false
  oauth2: false
  oidc: false
  mtls: false
schemes:
- name: Anonymous
  type: none
  applies_to:
  - GET https://hpsf.io/wp-json/
  - GET https://hpsf.io/wp-json/tribe/events/v1/events
  - GET https://hpsf.io/wp-json/tribe/events/v1/venues
  - GET https://hpsf.io/wp-json/tribe/events/v1/organizers
  - GET https://hpsf.io/wp-json/tribe/events/v1/categories
  - GET https://hpsf.io/wp-json/tribe/events/v1/tags
  - GET https://hpsf.io/wp-json/tribe/events/v1/doc
  - GET https://hpsf.io/wp-json/tec/v1/docs
  note: >-
    No credential of any kind is required to read the events surface or either contract. Verified with
    unauthenticated GETs returning HTTP 200 on 2026-09-13.
- name: BasicAuth
  type: http
  scheme: basic
  header: 'Authorization: Basic <base64 username:application-password>'
  declared_in: openapi/hpsf-tec-events-api-openapi.yml
  mechanism: WordPress Application Passwords
  authorization_endpoint: https://hpsf.io/wp-admin/authorize-application.php
  authorization_endpoint_source: >-
    Declared by the host itself in the authentication block of https://hpsf.io/wp-json/
  applies_to: All POST/PUT/PATCH/DELETE operations across tribe/events/v1 and tec/v1.
  public_onboarding: false
  note: >-
    Application Passwords are issued from inside the WordPress admin to an existing site user. HPSF
    publishes no process for a third party to obtain one, so the write half of both contracts is
    documented but unreachable from outside the foundation's own web team.
gated_surfaces:
- namespace: wp-abilities/v1
  status: 401
  code: rest_forbidden
  note: >-
    The WordPress Abilities registry is installed and registered on this host. An anonymous GET of
    /wp-json/wp-abilities/v1/abilities returns 401 - the ability list, which is the closest thing this
    host has to a machine-callable tool catalog, requires an authenticated WordPress user.
- namespace: tec/v1
  status: 400
  code: missing_experimental_endpoint_acknowledgement
  note: >-
    Not an authentication gate. The namespace is fenced behind an undocumented acknowledgement header
    for experimental endpoints, and rejects anonymous callers before any credential is considered.
- namespaces: [activity-log/v1, objectcache/v1, liquidweb/harbor/v1, regenerate-thumbnails/v1, wp-site-health/v1, tec/v2/onboarding, tribe/event-aggregator/v1, tribe/zapier/v1, tribe/power-automate/v1]
  note: >-
    Site-administration and integration plugin routes, all permission-gated to a logged-in WordPress
    administrator. Present in the route index; not a public API surface.
absent:
  api_key_header: null
  oauth_scopes: null
  note: >-
    scopes/ is deliberately not written. There is no oauth2 securityScheme in either contract and no
    OAuth documented anywhere, so an OAuthScopes artifact would be an empty claim.
evidence:
- url: https://hpsf.io/wp-json/tribe/events/v1/events?per_page=1
  status: 200
  note: Anonymous read succeeded with no credential.
- url: https://hpsf.io/wp-json/
  status: 200
  note: 'authentication block names application-passwords with its authorization endpoint.'
- url: https://hpsf.io/wp-json/wp-abilities/v1/abilities
  status: 401
- url: https://hpsf.io/.well-known/oauth-authorization-server
  status: 404
- url: https://hpsf.io/.well-known/openid-configuration
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hpsf-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.