Monite · Authentication Profile

Monite Authentication

Authentication

Monite secures its APIs with http and oauth2-style token endpoint across 1 declared security scheme, as derived from its OpenAPI definitions.

CompanyEmbedded FinanceInvoicingAccounts PayablePaymentsB2BFintechSaaS
Methods: http, oauth2-style token endpoint Schemes: 1 OAuth flows: API key in:

Security Schemes

HTTPBearer http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-10-09'
method: searched
source: https://docs.monite.com/api/concepts/authentication
docs: https://docs.monite.com/api/concepts/authentication
summary:
  types:
  - http
  - oauth2-style token endpoint
  description: All requests use a Bearer token generated by Monite from a Client ID and Client Secret created in the Monite Partner Portal. Tokens come from POST /auth/token (no auth headers required) and can be revoked with POST /auth/revoke. HTTPS only.
schemes:
- name: HTTPBearer
  type: http
  scheme: bearer
  sources:
  - openapi/monite-openapi.yml
  - https://docs.monite.com/api/concepts/authentication
token_endpoint:
  url: https://api.monite.com/v1/auth/token
  sandbox_url: https://api.sandbox.monite.com/v1/auth/token
  operation: post_auth_token
  revoke_operation: post_auth_revoke
  grant_types:
  - name: client_credentials
    description: Standard OAuth 2.0 grant for backend-to-backend communication; yields a partner-level token with the highest privileges (required for /entities and partner /settings operations).
  - name: entity_user
    description: Custom Monite grant type; requires entity_user_id and yields an entity-user token whose permissions come from the user's role (RBAC).
  token_lifetime: expires_in is returned in seconds (example value 1800); docs describe tokens as short-lived with an adjustable lifespan.
authorization_model:
  type: RBAC
  description: Entity-user tokens are checked against role permissions (not_allowed, allowed, allowed_for_own) per object_type and action. See scopes/monite-scopes.yml.
required_headers:
- name: x-monite-version
  description: API version, required on every request.
- name: x-monite-entity-id
  description: Entity that owns the resource; required to access entity-owned resources.
credentials_source: https://docs.monite.com/get-started/credentials

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/monite-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.