Kore.ai · Authentication Profile
Koreai Authentication
Authentication
Kore.ai declares 0 security scheme(s) across its OpenAPI definitions.
CompanyArtificial IntelligenceConversational AIAgentsAgent PlatformContact CenterCustomer ExperienceEmployee ExperienceVoiceAutomationMCPEnterprise Software
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-08-23'
method: searched
source: https://docs.kore.ai/ai-for-service/apis/automation/api-introduction
docs:
- https://docs.kore.ai/ai-for-service/apis/automation/api-introduction
- https://github.com/Koredotcom/docs-v2/blob/main/agent-platform/drafts/api-reference/index.mdx
note: >-
Kore.ai runs two API estates with two different auth models. AI for Service (the XO /
Automation AI platform on platform.kore.ai) authenticates with a signed JWT minted from
a JWT App's Client ID + Secret and passed in a non-standard `auth` header. The Agent
Platform (Artemis, on agents.kore.ai) authenticates with bearer JWTs or prefixed API
keys. Both are documented publicly; neither uses OAuth 2.0 for inbound API access, so
there is no OAuth scope surface to capture in scopes/.
estates:
- name: AI for Service platform APIs
host: https://platform.kore.ai
schemes:
- id: jwt-app
type: apiKey
in: header
name: auth
description: >-
A JWT signed with the JWT App's Client Secret, carrying the Client ID. Created under
App Settings > Dev Tools > Web/Mobile SDK, or in the Admin Console under
Security & Control > API Scopes > Manage Apps.
signing_algorithms_configurable: true
options:
- id: enforce-jti
description: When enabled, the platform only accepts requests carrying a JTI (JWT ID) claim and rejects the rest.
- id: enforce-jwe
description: JWE encryption of the token.
- id: payload-encryption
description: >-
AES-256 encryption of request and response payloads. The client supplies a public
key; the platform generates an AES-256 key, encrypts the payload with it, and
returns the AES key wrapped with the client's public key. Supported on a named
subset of endpoints (session history, analytics, conversation details, LLM usage
logs, and the user/role admin endpoints).
authorization_model:
style: assigned-scopes
description: >-
Access is not a single flat key. Each JWT App is assigned API scopes in two
namespaces — Platform API Scopes (App Builder features) and Admin Console API Scopes
(account administration). The provider publishes a per-API scope matrix: every row of
the Automation AI, Contact Center AI, Agent AI, Quality AI and Case Management API
lists names the Platform Scope and Admin Console Scope required.
reference: https://docs.kore.ai/ai-for-service/apis/api-list
- name: Agent Platform (Artemis) runtime + management APIs
host: https://agents.kore.ai
schemes:
- id: jwt-bearer
type: http
scheme: bearer
in: header
name: Authorization
description: JWT bearer token issued after user login.
- id: api-key-bearer
type: http
scheme: bearer
in: header
name: Authorization
description: Long-lived API key prefixed `abl_`, passed as a bearer token.
key_prefix: abl_
- id: api-key-header
type: apiKey
in: header
name: X-API-Key
description: Service-to-service API key header. Also accepts an origin-restricted public widget key.
key_prefix: ak_
- id: public-widget-key
type: apiKey
in: header
name: X-Public-Key
description: >-
Origin-restricted public key, safe in client-side code, exchanged on
POST /api/v1/sdk/init for a short-lived SDK session token. Scoped to one project;
the runtime validates the Origin header on every SDK request against a configured
allowedOrigins list.
key_prefix: pk_
- id: sdk-session-token
type: apiKey
in: header
name: X-SDK-Token
description: Short-lived token for embedded widget sessions.
key_prefix: sdk_
- id: callback-signature
type: http
scheme: hmac
in: header
name: x-callback-signature
description: >-
HMAC-SHA256 of the request body keyed on the suspension's callback secret, formatted
`sha256=<hex>`. Verifies inbound human-task/tool callbacks; a failed verification
returns 401.
spec_declared:
file: openapi/koreai-abl-runtime-conversation-openapi.json
scheme: ApiKeyAuth (apiKey, header, x-api-key)
note: >-
The three published specs declare only the x-api-key apiKey scheme. The provider's
own API reference documents five more credential types; the spec is thinner than the
prose, which is why this artifact is method searched rather than derived.
oauth2: false
openid_connect: false
mtls: false
sso_for_platform_users:
supported: true
note: SSO, RBAC and MFA for platform (human) users are listed on the Kore.ai trust center. This is console access, not API authentication.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/koreai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.