Lithium · Authentication Profile

Lithium Authentication

Authentication

Lithium secures its APIs with http and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and clientCredentials flow(s).

CompanyMarTechCommunitySocial-MediaCustomer EngagementCustomer-SupportChatbotsMessagingAnalyticsMarketing
Methods: http, oauth2 Schemes: 3 OAuth flows: authorizationCode, clientCredentials API key in:

Security Schemes

sec0 http
scheme: basic
sec0 oauth2
· flows: clientCredentials
oauth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-19'
method: searched
source: openapi/lithium-care-analytics-reports-openapi.json, openapi/lithium-care-conversation-tag-rules-v2-openapi.json,
  openapi/lithium-care-secure-forms-api-v2-openapi.json, openapi/lithium-care-supervisor-reports-api-openapi.json,
  openapi/lithium-marketing-beta-analytics-api-openapi.json, openapi/lithium-marketing-conversations-api-v1-openapi.json,
  openapi/lithium-marketing-conversations-openapi.json, openapi/lithium-marketing-crm-openapi.json,
  openapi/lithium-marketing-introspection-api-openapi.json, openapi/lithium-marketing-labelsets-api-openapi.json,
  openapi/lithium-marketing-notification-service-openapi.json, openapi/lithium-marketing-stream-api-openapi.json
summary:
  types:
  - http
  - oauth2
  oauth2_flows:
  - authorizationCode
  - clientCredentials
schemes:
- name: sec0
  type: http
  scheme: basic
  sources:
  - openapi/lithium-care-analytics-reports-openapi.json
  - openapi/lithium-care-conversation-tag-rules-v2-openapi.json
  - openapi/lithium-care-secure-forms-api-v2-openapi.json
  - openapi/lithium-care-supervisor-reports-api-openapi.json
- name: sec0
  type: oauth2
  flows:
  - flow: clientCredentials
    tokenUrl: https://example.com/oauth2/token
    scopes: 0
  sources:
  - openapi/lithium-marketing-beta-analytics-api-openapi.json
  - openapi/lithium-marketing-conversations-openapi.json
  - openapi/lithium-marketing-crm-openapi.json
  - openapi/lithium-marketing-introspection-api-openapi.json
  - openapi/lithium-marketing-labelsets-api-openapi.json
  - openapi/lithium-marketing-notification-service-openapi.json
  - openapi/lithium-marketing-stream-api-openapi.json
- name: oauth2
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.spredfast.com/v3/oauth/authorize
    tokenUrl: https://login.spredfast.com/v3/oauth/token
    scopes: 1
  sources:
  - openapi/lithium-marketing-conversations-api-v1-openapi.json

docs:
  care_jwt: https://developer.khoros.com/khoroscaredevdocs/docs/jwt-authentication
  care_overview: https://developer.khoros.com/khoroscaredevdocs/docs/khoros-care-integration-overview
  community_api_apps: https://developer.khoros.com/khorosauroradevdocs/docs/generating-api-credentials-with-api-apps
  marketing_events_auth: https://developer.khoros.com/khorosmarketingdevdocs/docs/events-authentication

documented_models:
  - product: Khoros Care
    schemes: [http-basic, jwt]
    detail: >-
      Care v1 and v2 APIs use HTTP Basic against the per-instance
      {instance}.response.lithium.com host. The Automation Framework's Bot API v3 on
      api.app.lithium.com uses a signed JSON Web Token (header/payload/signature) instead —
      the documentation is explicit that only Bot API v3 uses JWT. The Care Authentication
      API v2 (/api/v2/tokens) exchanges credentials for a token.
    docs: https://developer.khoros.com/khoroscaredevdocs/docs/jwt-authentication
  - product: Khoros Marketing
    schemes: [oauth2]
    detail: >-
      OAuth 2.0 against login.spredfast.com. Token introspection is available at
      https://api.spredfast.com/v2/whoami. Tenancy is carried in x-sf-company-id /
      x-sf-initiative / x-sf-user-email request headers alongside the token.
  - product: Khoros Community
    schemes: [session, api-app-credentials]
    detail: >-
      Community v2 rejects anonymous calls with its JSON error envelope (code 203).
      Credentials are provisioned as API apps through the community admin. Documentation is
      behind the Atlas login.
  - product: Khoros Flow
    schemes: [api-key]
    detail: Token-based access to the flow.ai REST API.

caveats:
  - >-
    The `sec0` clientCredentials scheme repeated across seven Khoros Marketing definitions
    declares tokenUrl https://example.com/oauth2/token with an empty scopes map. That is a
    ReadMe API-designer placeholder, not a real authorization server — the working OAuth
    endpoints are the login.spredfast.com pair on the Conversations API v1 definition.
  - >-
    Only 12 of the 28 harvested definitions declare any security scheme at all; the
    remaining 16 (mostly the per-instance Care v2 APIs) document authentication in prose
    only.

related:
  scopes: ../scopes/lithium-scopes.yml
  conventions: ../conventions/lithium-conventions.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lithium-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.