Iru · Authentication Profile

Iru Authentication

Authentication

Iru secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

CompanyDevice ManagementMobile Device Managementapple-managementEndpoint Securityendpoint-detection-responseVulnerability ManagementCompliance AutomationWorkforce IdentityIT OperationsMCPagent-native
Methods: http Schemes: 1 OAuth flows: API key in: header

Security Schemes

bearerAuth http
scheme: bearer · in: header ()

Source

Authentication Profile

Raw ↑
generated: '2026-07-19'
method: searched
source: https://docs.iru.com/en/endpoint/api/iru-api-overview.md
docs: https://support.kandji.io/kb/kandji-api
summary:
  types: [http]
  scheme: bearer
  api_key_in: [header]
  oauth2_flows: []
schemes:
  - name: bearerAuth
    type: http
    scheme: bearer
    in: header
    header: Authorization
    format: "Bearer <token>"
    description: >-
      Iru Endpoint uses tenant-level bearer tokens to control access to the API.
      Tokens are created in the Access area (Account Menu > Access > API tokens
      tab). Each token has a Name and Description and is shown exactly once at
      creation ("You will not be able to see the token or the MCP configuration
      again"). Tokens can optionally be MCP-enabled for use with MCP clients.
    sources:
      - https://docs.iru.com/en/endpoint/api/iru-api-overview.md
permissions:
  model: per-token scoped permissions (not OAuth scopes)
  description: >-
    Each API token carries a configurable set of permissions, grouped into
    sections (for example "Blueprints Management"). Checking or unchecking a
    section header toggles every permission in that section. Permissions are
    edited on the token detail view (Configure / Edit) after creation and can be
    revoked at any time. This is a permission-grant model over a bearer token,
    not an OAuth2 scope surface, so no scopes/ artifact is emitted.
token_host:
  form: <subdomain>.api.kandji.io
  example: accuhive.api.kandji.io
  note: >-
    The tenant-specific API URL is displayed on the API tokens page after the
    first token is created.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/iru-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.