Lumos · Authentication Profile
Lumos Authentication
Authentication
Lumos runs TWO independent credential systems on one host. The REST API takes a static bearer API key prefixed `lsk_`. The two hosted MCP servers take an OAuth 2.1 access token from b.app.lumosidentity.com and explicitly refuse API keys. An agent that has a working REST key still cannot call the MCP servers, and vice versa.
Lumos secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions.
Access ManagementAccess ReviewsDeprovisioningIdentity GovernanceIdentity PlatformLeast PrivilegeProvisioningSaaS ManagementShadow IT
Methods: http, oauth2
Schemes: 2
OAuth flows:
API key in:
Security Schemes
HTTPBearer http
LumosOAuth oauth2
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.