IPstack · Authentication Profile
Ipstack Authentication
Authentication
Two entirely different authentication models sit behind one product. The REST API uses a single static access key passed as a URL QUERY PARAMETER — the weakest of the common API key placements, since the credential lands in proxy logs, browser history and Referer headers. The MCP server in front of the same data uses a real OAuth 2.0 deployment with discovery, PKCE and dynamic client registration.
IPstack declares 2 security scheme(s) across its OpenAPI definitions.
GeocodingIP GeolocationLocationThreat IntelligenceNetworkingMCPPublic APIs
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
access_key apiKey
oauth2
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.