Motomarks · Authentication Profile
Motomarks Authentication
Authentication
Motomarks declares 3 security scheme(s) across its OpenAPI definitions.
AutomotiveLogoImage CDNManufacturerBrand AssetsImageCDNDeveloper ToolsAgent-NativeMCPReference Data
Methods:
Schemes: 3
OAuth flows:
API key in:
Security Schemes
http
scheme: bearer
token apiKey
· in: query ()
oauth2
· flows:
Source
Authentication Profile
name: Motomarks Authentication
generated: '2026-09-09'
method: searched
source: https://motomarks.io/docs/platform/api-keys
docs: https://motomarks.io/docs/platform/api-keys
note: >-
No OpenAPI is published; profile assembled from the API-keys, API-reference and MCP docs plus live probes of
the OAuth discovery documents and the gated API host (api.motomarks.io answers 403 {"error":"invalid_token"}
without a key).
schemes:
- id: secret-key-bearer
type: http
scheme: bearer
key_prefix: sk_
surfaces: [JSON API, MCP Server (headless)]
description: >-
Secret keys (sk_...) are server-side only, sent as "Authorization: Bearer YOUR_SECRET_KEY". They
authenticate the JSON API (api.motomarks.io) and headless connections to the MCP server. Full account
access; never for client-side code.
- id: publishable-key-token
type: apiKey
in: query
name: token
key_prefix: pk_
surfaces: [Image CDN]
description: >-
Publishable keys (pk_...) are safe to expose client-side and authenticate the Image CDN as a ?token=
query parameter. On Pro and Enterprise plans each publishable key can carry a hostname allowlist
(Origin/Referer-checked domain restrictions; wildcard subdomains supported; localhost always permitted).
- id: oauth2
type: oauth2
surfaces: [MCP Server]
flows:
authorizationCode:
authorizationUrl: https://motomarks.io/api/auth/mcp/authorize
tokenUrl: https://motomarks.io/api/auth/mcp/token
refreshUrl: https://motomarks.io/api/auth/mcp/token
scopes:
openid: OpenID Connect identity
profile: Basic profile
email: Email address
offline_access: Refresh tokens
description: >-
OAuth 2.1 authorization-code with PKCE (S256) and dynamic client registration (registration_endpoint
published) per the MCP authorization spec. Discovery via /.well-known/oauth-authorization-server and
/.well-known/oauth-protected-resource on motomarks.io (both HTTP 200, saved under well-known/).
optional_headers:
- name: X-Motomarks-Referer
description: Optional analytics-only attribution of server-side requests to a site or app; never access control.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/motomarks-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.