NiKang Therapeutics · Authentication Profile
Nikang Therapeutics Authentication
Authentication
NiKang Therapeutics declares 0 security scheme(s) across its OpenAPI definitions.
CompanyBiotechnologyPharmaceuticalsOncologyPrecision MedicineDrug DiscoveryTargeted Protein DegradationClinical TrialsLife Sciencescontent-api
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-08-26'
method: probed
source: >-
The `authentication` array in the WordPress REST index at https://www.nikangtx.com/wp-json (empty),
plus live anonymous requests against every route family on 2026-08-26. 0-working/derive-authentication.py
was run first and correctly found zero securitySchemes, because there are none to find — this file
records what was observed at the wire instead.
docs: https://developer.wordpress.org/rest-api/using-the-rest-api/authentication/
note: >-
NiKang Therapeutics issues no API credentials of any kind. There is no developer portal, no signup,
no key request form and no OAuth client registration. The catalogued surface is anonymous read-only
content; authentication exists on this deployment only as the wall that separates that public
content from the WordPress administration surface, and there is no public path to get past it.
schemes: []
profile:
style: none
anonymous_access: true
credentials_available_to_the_public: false
detail: >-
The /wp-json index reports `"authentication": []` — no scheme is advertised for anonymous
discovery. Every read operation described in openapi/ was executed with no credentials and no
cookie and returned HTTP 200.
cors:
access_control_allow_headers: 'Authorization, X-WP-Nonce, Content-Disposition, Content-MD5, Content-Type'
detail: >-
The CORS preflight allow-list names `Authorization` and `X-WP-Nonce`, which is WordPress core
boilerplate advertising the schemes core would accept if a credential existed. It is not an
offer of credentials to the public and must not be read as one.
gated_surface:
detail: >-
These routes are registered and visible in the public route index but return 401 anonymously.
They are excluded from openapi/ and are recorded here so the boundary is explicit.
observed:
- path: /wp/v2/users
status: 401
code: rest_user_cannot_view
- path: /wp/v2/settings
status: 401
code: rest_forbidden
- path: /wp/v2/block-types
status: 401
code: rest_block_type_cannot_view
- path: /wp-abilities/v1/abilities
status: 401
code: rest_forbidden
- path: /wp-site-health/v1/tests/background-updates
status: 401
code: rest_forbidden
- path: /oembed/1.0/proxy
status: 401
code: rest_forbidden
consequence: >-
/wp/v2/users being 401-gated is the one gap that matters for a consumer: posts carry an integer
`author` id that cannot be resolved to a name without credentials. Author display data is only
reachable indirectly, and the dt_team collection — not the users collection — is where NiKang's
named people actually live.
write_surface:
anonymous: none
detail: >-
POST, PUT, PATCH and DELETE are registered on the post-like and term routes but every one of them
requires an authenticated user with the matching capability. There is no anonymous write path at
all, which is why reversibility, dry-run and idempotency are all `na` in
conventions/nikang-therapeutics-conventions.yml.
cross_links:
conventions: conventions/nikang-therapeutics-conventions.yml
errors: errors/nikang-therapeutics-problem-types.yml
scopes: null
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/nikang-therapeutics-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.