Mlsgrid · Authentication Profile
Mlsgrid Authentication
Authentication
Mlsgrid secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
Real EstateProperty ListingsMLSRESOData ReplicationODataHousingData LicensingIDXProperty Data
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
bearerAuth http
scheme: bearer
Source
Authentication Profile
generated: '2026-09-17'
method: searched
docs:
- https://docs.mlsgrid.com/master.md
- https://docs.mlsgrid.com/api-documentation/api-version-2.0.md
- https://docs.mlsgrid.com/data-consumer-guides/how-to-register-and-activate-an-mls-grid-data-consumer-account.md
source: https://docs.mlsgrid.com/master.md + openapi/mlsgrid-lookup-api-openapi.yml, openapi/mlsgrid-media-api-openapi.yml, openapi/mlsgrid-member-api-openapi.yml,
openapi/mlsgrid-metadata-api-openapi.yml, openapi/mlsgrid-office-api-openapi.yml, openapi/mlsgrid-openhouse-api-openapi.yml,
openapi/mlsgrid-property-api-openapi.yml
summary:
types:
- http
schemes:
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: OAuth2
description: Long-lived OAuth 2.0 bearer token issued via the MLS Grid web application token
tab.
sources:
- openapi/mlsgrid-lookup-api-openapi.yml
- openapi/mlsgrid-media-api-openapi.yml
- openapi/mlsgrid-member-api-openapi.yml
- openapi/mlsgrid-metadata-api-openapi.yml
- openapi/mlsgrid-office-api-openapi.yml
- openapi/mlsgrid-openhouse-api-openapi.yml
- openapi/mlsgrid-property-api-openapi.yml
model:
flavor: simplified-oauth2-bearer
header: 'Authorization: Bearer <access_token>'
token_lifetime: long-lived
token_endpoint: null
authorization_endpoint: null
refresh_flow: false
scopes: false
scopes_note: >-
No scope surface exists, so no scopes/ artifact is written. Entitlement is not expressed in the
token - it arrives in the payload, per record, as MlgCanUse (IDX | VOW | BO | PT) and MlgCanView.
discovery:
openid_configuration: false
oauth_authorization_server: false
note: >-
Probed 2026-09-17 across www / api / docs / app.mlsgrid.com. 404 on www and docs, 401 on
api.mlsgrid.com (which authenticates every path including /.well-known/*), and the app host
answers 200 with its SPA shell. See well-known/mlsgrid-well-known.yml.
issuance:
self_serve: false
steps:
- Submit the interest form at https://www.mlsgrid.com/interest-form
- Sign the MLS Grid Master Data License Agreement in the licensing portal
- Create a data subscription and add a licensee
- Wait for the originating MLS to approve the licensee
- Read the long-lived token from the token tab of the approved subscription in app.mlsgrid.com
source: https://docs.mlsgrid.com/data-consumer-guides/how-to-register-and-activate-an-mls-grid-data-consumer-account.md
rotation: >-
Contact support@mlsgrid.com to have a token re-generated, which invalidates the old one. No
self-service rotation endpoint is published.
suspension: >-
Exceeding a published rate limit suspends the access token and emails the vendor account primary
contact; it is reinstated automatically once usage falls back within limits.
gotcha: >-
Compression is evaluated BEFORE authentication. A request without Accept-Encoding gzip returns
HTTP 400 COMPRESSION REQUIRED, not 401 - which reads as an auth failure to a client that only
checks for 401.
media_credential_reuse: >-
Media downloads must send a User-Agent header whose value is the OAuth 2 access token (enforced
from 2026-06-01), so the credential is carried in two different headers depending on the surface.
reverified_on: '2026-09-17'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mlsgrid-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.