Mydentify Public API · Authentication Profile
Mydentify Public Api Authentication
Authentication
Mydentify Public API declares 0 security scheme(s) across its OpenAPI definitions.
Product Discoverystartup directoriesLeaderboardsResearchSoftware-as-a-ServiceDeveloper Toolsagent-nativellms-txtAgent SkillsDirectories
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-08-09'
method: searched
source: openapi/mydentify-public-api-openapi-original.json
docs: https://mydentify.com/developers
summary:
types: []
model: anonymous
api_key_in: []
oauth2_flows: []
detail: >-
Mydentify's public API is deliberately keyless. The OpenAPI 3.1 document declares a top-level
`security: []` and defines no `components.securitySchemes`; the developer guide states "No API
key required — public read routes work without a token, login, or paid plan." This applies to
the write surface too: the diagnostic/submission workflow (POST /api/imports*) is
unauthenticated, with the Idempotency-Key header and the durable import id acting as the
only client-held identifiers.
schemes: []
transport:
https_required: true
hsts: true
hsts_max_age: 31536000
tls_version: TLSv1.3
cors:
enabled: true
allow_origins: ['*']
scope: directory JSON endpoints
source: openapi x-cors extension
authorization_model:
public_read: unrestricted
writes:
surface: POST /api/imports, /api/imports/{id}/{retry,manual-review,goals,verify-badge}
control: >-
No credential. Access to an import is bearer-by-URL — knowledge of the UUID import id
returned in ImportAccepted.statusUrl / eventsUrl. Publication is additionally gated by an
out-of-band proof: Mydentify verifies a followed backlink or the official listing badge on
the submitted page before a free listing goes live.
escalation: POST /api/imports/{id}/verify-badge, POST /api/imports/{id}/manual-review
agent_boundaries:
source: https://mydentify.com/ai.txt
read_only: no user confirmation required
external_actions: >-
Submission, intent confirmation, account changes, payment and sponsorship require explicit
user approval.
excluded_from_public_api: ['/admin/*', '/dashboard/*', '/diagnostics/*', '/claim/*', authenticated responses, billing data]
gaps:
- No authenticated tier is published, so there is no documented way to raise limits, claim a
listing programmatically, or read private diagnostic sessions via the API.
- There is no rate-limit contract to accompany the anonymous write surface; the only throttle
signal in the spec is a 429 on the retry operation.
x-evidence:
fetched: '2026-08-09'
urls:
- {url: 'https://mydentify.com/openapi.json', http_status: 200}
- {url: 'https://mydentify.com/developers', http_status: 200}
- {url: 'https://mydentify.com/api/imports/dry-run', http_status: 200, note: 'anonymous POST accepted, returned a DryRunResult'}
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mydentify-public-api-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.