Octane AI · Authentication Profile

Octane Ai Authentication

Authentication

Octane AI secures its APIs with apiKey across 4 declared security schemes, as derived from its OpenAPI definitions.

CompanyShopifyE-CommerceProduct RecommendationsQuizzesPersonalizationZero-Party DataMarketingConversion OptimizationArtificial Intelligence
Methods: apiKey Schemes: 4 OAuth flows: API key in: account-settings

Security Schemes

account_api_key apiKey
· in: account-settings ()
webhook_secret apiKey
· in: account-settings ()
bot_id apiKey
· in: account-settings ()
shopify_oauth oauth2

Source

Authentication Profile

octane-ai-authentication.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://help.octaneai.com/en/articles/5679805-how-do-i-find-my-account-s-api-key-webhook-secret.md
docs: https://help.octaneai.com/en/articles/5679805-how-do-i-find-my-account-s-api-key-webhook-secret
summary:
  types:
  - apiKey
  api_key_in:
  - account-settings
  oauth2_flows: []
  notes: >-
    Octane AI is a Shopify quiz / product-recommendation application. It does not
    publish a public REST API or OpenAPI. Integration authentication is handled
    through a per-account API key plus a webhook secret (documented in the help
    center as "How do I find my account's API key & webhook secret?"). These
    credentials are used by outbound integrations (Zapier, Alloy, marketing
    platforms) and to verify inbound webhook signatures. The app itself is
    installed and authorized via Shopify OAuth as an embedded Shopify app.
schemes:
- name: account_api_key
  type: apiKey
  in: account-settings
  description: >-
    Per-account API key surfaced in the Octane AI dashboard account settings,
    used to authenticate integrations and automation platform connections.
  sources:
  - https://help.octaneai.com/en/collections/3929090-integrations
- name: webhook_secret
  type: apiKey
  in: account-settings
  description: >-
    Per-account webhook signing secret used to verify the authenticity of
    outbound webhook payloads delivered to connected integration partners.
  sources:
  - https://help.octaneai.com/en/collections/3929090-integrations
- name: bot_id
  type: apiKey
  in: account-settings
  description: >-
    Per-account identifier ("bot ID") that scopes the API key to one Octane AI
    account; it also appears in the account's dashboard URL. Zapier and Alloy both
    require API key + bot ID together to authenticate a connection.
  sources:
  - https://help.octaneai.com/en/articles/5679805-how-do-i-find-my-account-s-api-key-webhook-secret
  - https://help.octaneai.com/en/articles/5683555-getting-started-with-zapier
- name: shopify_oauth
  type: oauth2
  description: >-
    App installation and store authorization is performed through the Shopify
    app OAuth flow when a merchant installs Octane AI from the Shopify App Store.
  sources:
  - https://octaneai.com/integrations
credential_locations:
- Dashboard → Settings → General settings (API key + webhook secret)
- Dashboard → Integrations → Actions → Setup (API key + webhook secret + bot ID)
access_gates:
  developer_tools: >-
    octane.quiz.* JavaScript events and custom CSS/JS require the Octane AI Plus
    or Enterprise plan.
  api_access: >-
    A general "API access" capability is advertised only on the Enterprise
    (contact-sales) tier at https://octaneai.com/pricing; no reference, base URL,
    or authentication contract for it is published anywhere public.
rotation_and_scoping:
  scopes: none-published
  rotation: not-documented
  note: >-
    A single API key per account, no scoping model, no documented rotation or
    revocation flow, and no documented signature algorithm for the webhook secret.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/octane-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.