Modal Labs Authentication
Modal has THREE distinct authentication surfaces and they are easy to confuse. (1) The control plane — the gRPC API the SDKs and CLI speak — authenticates with a token id + token secret pair created by `modal token new` and stored in ~/.modal.toml. (2) Deployed web endpoints on *.modal.run authenticate INBOUND callers with Proxy Tokens presented as Modal-Key and Modal-Secret headers, enforced by Modal's edge proxy before the request reaches the container. (3) Modal signs OUTBOUND OIDC identity tokens so a running Function can prove who it is to an external service — Modal is the issuer there, not the verifier. There is no OAuth authorization-code flow and no user-facing OAuth scope surface, so scopes/ is deliberately absent.
Modal declares 4 security scheme(s) across its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.