Linode · Authentication Profile

Linode Authentication

Authentication

Linode secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

Cloud ComputingInfrastructure-as-a-ServiceVirtual MachinesKubernetesObject StorageBlock StorageDNSManaged DatabaseNetworkingGPULoad BalancerDeveloper Tools
Methods: http, oauth2 Schemes: 2 OAuth flows: authorizationCode API key in:

Security Schemes

personalAccessToken http
scheme: bearer
oauth oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: https://techdocs.akamai.com/linode-api/reference/get-started
summary:
  types:
  - http
  - oauth2
  oauth2_flows:
  - authorizationCode
schemes:
- name: personalAccessToken
  type: http
  scheme: bearer
  description: A personal access token generated from the Linode Cloud Manager that grants access to the API based
    on the token's scopes.
  sources:
  - openapi/_original/linode-api-v4-official-openapi.json
  - https://techdocs.akamai.com/linode-api/reference/get-started
- name: oauth
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.linode.com/oauth/authorize
    tokenUrl: https://login.linode.com/oauth/token
    scopes: 28
  description: OAuth 2.0 authentication for third-party applications.
  sources:
  - openapi/_original/linode-api-v4-official-openapi.json
  - https://techdocs.akamai.com/linode-api/reference/get-started
docs: https://techdocs.akamai.com/linode-api/reference/get-started
derived_from: openapi/_original/linode-api-v4-official-openapi.json (components.securitySchemes)
note: 'Two credential models, both bearer tokens on the Authorization header. Personal access tokens are created
  in Cloud Manager (or via post-personal-access-token) with a fixed expiry chosen at creation that cannot be changed
  afterwards, and a per-category read/write access level that also cannot be changed afterwards. OAuth 2.0 authorization
  code (RFC 6749) is for third-party applications: login.linode.com is the authorization server, api.linode.com
  the resource server, access tokens live two hours, and only the private (confidential) client flow issues a refresh
  token - the public client flow requires the user to log in again. Since Identity and Access reached GA on 2026-03-31,
  OAuth scope is layered over an RBAC permission model, so an operation can fail on the permission even when the
  scope is present; each operation reference page names both. Some catalog operations (regions, plan types, pricing)
  need no credential at all.'
token_ttl:
  oauth_access_token: 2 hours
  oauth_refresh_token: issued only to private/confidential clients
  personal_access_token: fixed expiry chosen at creation, not extendable
authorization_model:
  style: RBAC (Identity and Access in Akamai Cloud) layered under OAuth scopes
  ga_date: '2026-03-31'
  docs: https://techdocs.akamai.com/cloud-computing/docs/identity-and-access-cm
scopes_artifact: scopes/linode-scopes.yml
unauthenticated_surface:
  available: true
  examples:
  - /v4/regions
  - /v4/linode/types
  - /v4/volumes/types
  - /v4/network-transfer/prices
  note: 'Verified live on 2026-09-17: these return 200 with no Authorization header.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/linode-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.