Space Frontiers · Authentication Profile
Machinelibrary Ai Authentication
Authentication
Space Frontiers secures its APIs with apiKey, http, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions.
ResearchScholarly SearchFull-Text SearchRetrievalRAGPatentsDocumentsOCRDocument RecognitionMCPA2AAgent-NativeAI AgentsDataSearch
Methods: apiKey, http, oauth2
Schemes: 3
OAuth flows:
API key in: header
Security Schemes
api_key apiKey
· in: header (X-Api-Key)
bearer_auth http
scheme: bearer
oauth2 oauth2
· flows: ,
Source
Authentication Profile
generated: '2026-10-03'
method: searched
source: openapi/machinelibrary-ai-openapi.yml, openapi/machinelibrary-ai-recognition-openapi.yml (securitySchemes) upgraded with https://api.machinelibrary.ai/auth.md, the RFC 8414 / RFC 9728 metadata under well-known/, https://machinelibrary.ai/privacy (token lifetimes) and the MCP repo README/smithery.yaml (key prefix)
docs: https://api.machinelibrary.ai/auth.md
keys_page: https://machinelibrary.ai/keys
summary:
types: [apiKey, http, oauth2]
api_key_in: [header]
one_credential_three_surfaces: The same API key authenticates the REST API (X-Api-Key or Bearer), the MCP server (Authorization Bearer) and the A2A agent (bearer or X-Api-Key security schemes in the card).
sign_in_methods: Google, GitHub, or email (press page); the /keys page 302s to /auth/signin for anonymous visitors.
schemes:
- name: api_key
type: apiKey
in: header
parameter: X-Api-Key
description: Machine Library API key from https://machinelibrary.ai/keys.
key_prefix: ml_ followed by 48 hexadecimal characters, shown once at creation; keys issued before 2026-09-29 (id:ml_...) remain valid (docs/api/operations, 2026-10-03). The sf_live_ shape survives only in older MCP README / smithery.yaml examples.
expiry: Long-lived; does not expire automatically, revocable from account settings (privacy policy section 4).
sources: [openapi/machinelibrary-ai-openapi.yml, openapi/machinelibrary-ai-recognition-openapi.yml]
- name: bearer_auth
type: http
scheme: bearer
bearerFormat: API key or OAuth 2.0 access token
description: Send the same API key, or an OAuth 2.0 access token, as a Bearer token.
sources: [openapi/machinelibrary-ai-openapi.yml, openapi/machinelibrary-ai-recognition-openapi.yml]
- name: oauth2
type: oauth2
issuer: https://api.machinelibrary.ai
issuer_note: Re-verified 2026-10-03. The issuer moved from https://api.spacefrontiers.org (2026-09-19) to https://api.machinelibrary.ai; the legacy api.spacefrontiers.org, spacefrontiers.org and mcp.spacefrontiers.org metadata all name the new issuer.
metadata: https://api.machinelibrary.ai/.well-known/oauth-authorization-server
protected_resource_metadata:
- https://mcp.machinelibrary.ai/.well-known/oauth-protected-resource
- https://machinelibrary.ai/.well-known/oauth-protected-resource
flows:
authorizationCode:
authorizationUrl: https://api.machinelibrary.ai/v2/oauth/authorize
tokenUrl: https://api.machinelibrary.ai/v2/oauth/token
refreshUrl: https://api.machinelibrary.ai/v2/oauth/token
revocationUrl: https://api.machinelibrary.ai/v2/oauth/revoke
registrationUrl: https://api.machinelibrary.ai/v2/oauth/register
scopes:
search: Search the corpus and retrieve research documents using the user's account credits.
pkce: S256 required
client_auth: none (public clients; token_endpoint_auth_methods_supported [none]); new client IDs start with ml_oauth_
dynamic_client_registration: RFC 7591 at the registrationUrl; the operations page notes public client registration does not verify the application's identity
resource_indicator: Set the OAuth resource to https://mcp.machinelibrary.ai (auth.md section 7)
service_auth (agent claim flow):
description: >-
For agents that cannot receive a browser callback. POST https://api.machinelibrary.ai/v2/agent/identity
{"type":"service_auth","login_hint":"<user email>"} returns a registration_id, a secret claim_token and a
claim {user_code (6 digits), verification_uri, expires_in 900, interval 5}. The user opens the verification
URI, signs in with the matching verified email, confirms the code and approves; the agent polls the token
endpoint with grant_type=urn:workos:agent-auth:grant-type:claim&claim_token=... honouring
authorization_pending / slow_down / access_denied / expired_token. Approval yields a one-hour access_token
plus a service-signed identity_assertion; renew with grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion=...
endpoints:
identity: https://api.machinelibrary.ai/v2/agent/identity (issuer metadata, 2026-10-03)
claim: https://api.machinelibrary.ai/v2/agent/identity/claim
claim_complete: https://api.machinelibrary.ai/v2/agent/identity/claim/complete (browser-only; agents must not call it)
constraints: Anonymous registration and external identity assertions are not accepted; the email is a login hint, not proof of identity.
token_lifetimes:
access_token: 3600 seconds
refresh_token: 30 days, rotating; reuse of a rotated token revokes the chain
authorization_code: deleted on exchange or after 60 seconds
audience_binding: Tokens are audience-bound to the requested MCP host (privacy policy section 4).
a2a_card_schemes:
bearer: http bearer — "Machine Library API key or OAuth 2.1 access token"
apiKey: header X-Api-Key
operation_security:
default: Every REST operation lists api_key OR bearer_auth (the Recognition operations inherit the same two schemes in the standalone spec); no operation is anonymous except GET /v1/pricing, which answered 200 unauthenticated on 2026-09-19.
unauthenticated_observations:
- {url: 'POST https://api.machinelibrary.ai/v2/search/', status: 401, body: '{"detail":"Unauthorized","status":"error"}'}
- {url: 'POST https://mcp.machinelibrary.ai/ tools/list', status: 401, www_authenticate: 'Bearer resource_metadata="https://mcp.machinelibrary.ai/.well-known/oauth-protected-resource"'}
- {url: 'POST https://machinelibrary.ai/a2a message/send', status: 200, note: answered with an agent message describing how to authenticate}
- {url: 'GET https://api.machinelibrary.ai/v1/pricing', status: 200}
safety_rules_from_provider:
- Never ask a user to share a password, session cookie, API key, authorization code, access token, refresh token, claim token, or identity assertion in chat. (auth.md)
- Store claim_token as a secret; show the user only the verification_uri and user_code together; do not email the code. (auth.md)
- Send the access token only to the configured MCP resource. (auth.md)
- On a 401, discard the credential, re-fetch both discovery documents, and restart registration if necessary. (auth.md)
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/machinelibrary-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.