Medium · Authentication Profile
Medium Authentication
Authentication
Medium offers two credentials for the same bearer header. Self-issued integration tokens are the recommended path and never expire; OAuth2 access tokens last 60 days and are refreshed with a non-expiring refresh token. Both are closed to new consumers — Medium stopped issuing new integration tokens and states it does not allow new integrations — so this profile documents how an EXISTING credential works, not a path a new developer can take today.
Medium secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions.
PublishingContentBloggingMediaSocialWritingAuthenticationDeprecated API
Methods: http, oauth2
Schemes: 2
OAuth flows:
API key in:
Security Schemes
bearerAuth http
oauth2 oauth2
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.