Kinde Authentication
The published contract declares a single http/bearer scheme, which under-describes what Kinde actually operates. In practice there are THREE distinct credential paths: an M2M client-credentials flow for the Management API, an end-user access token for the Account API, and k_live_-prefixed API keys for customer-registered APIs and the MCP server. The scheme description in the spec is also misleading — it says to use "a user token" obtained when users sign in, which is true for the Account API but wrong for the Management API, whose 169 operations require an M2M token with an audience parameter.
Kinde secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.