Octane AI · Authentication Profile
Octane Ai Authentication
Authentication
Octane AI secures its APIs with apiKey across 4 declared security schemes, as derived from its OpenAPI definitions.
CompanyShopifyE-CommerceProduct RecommendationsQuizzesPersonalizationZero-Party DataMarketingConversion OptimizationArtificial Intelligence
Methods: apiKey
Schemes: 4
OAuth flows:
API key in: account-settings
Security Schemes
account_api_key apiKey
· in: account-settings ()
webhook_secret apiKey
· in: account-settings ()
bot_id apiKey
· in: account-settings ()
shopify_oauth oauth2
Source
Authentication Profile
generated: '2026-08-13'
method: searched
source: https://help.octaneai.com/en/articles/5679805-how-do-i-find-my-account-s-api-key-webhook-secret.md
docs: https://help.octaneai.com/en/articles/5679805-how-do-i-find-my-account-s-api-key-webhook-secret
summary:
types:
- apiKey
api_key_in:
- account-settings
oauth2_flows: []
notes: >-
Octane AI is a Shopify quiz / product-recommendation application. It does not
publish a public REST API or OpenAPI. Integration authentication is handled
through a per-account API key plus a webhook secret (documented in the help
center as "How do I find my account's API key & webhook secret?"). These
credentials are used by outbound integrations (Zapier, Alloy, marketing
platforms) and to verify inbound webhook signatures. The app itself is
installed and authorized via Shopify OAuth as an embedded Shopify app.
schemes:
- name: account_api_key
type: apiKey
in: account-settings
description: >-
Per-account API key surfaced in the Octane AI dashboard account settings,
used to authenticate integrations and automation platform connections.
sources:
- https://help.octaneai.com/en/collections/3929090-integrations
- name: webhook_secret
type: apiKey
in: account-settings
description: >-
Per-account webhook signing secret used to verify the authenticity of
outbound webhook payloads delivered to connected integration partners.
sources:
- https://help.octaneai.com/en/collections/3929090-integrations
- name: bot_id
type: apiKey
in: account-settings
description: >-
Per-account identifier ("bot ID") that scopes the API key to one Octane AI
account; it also appears in the account's dashboard URL. Zapier and Alloy both
require API key + bot ID together to authenticate a connection.
sources:
- https://help.octaneai.com/en/articles/5679805-how-do-i-find-my-account-s-api-key-webhook-secret
- https://help.octaneai.com/en/articles/5683555-getting-started-with-zapier
- name: shopify_oauth
type: oauth2
description: >-
App installation and store authorization is performed through the Shopify
app OAuth flow when a merchant installs Octane AI from the Shopify App Store.
sources:
- https://octaneai.com/integrations
credential_locations:
- Dashboard → Settings → General settings (API key + webhook secret)
- Dashboard → Integrations → Actions → Setup (API key + webhook secret + bot ID)
access_gates:
developer_tools: >-
octane.quiz.* JavaScript events and custom CSS/JS require the Octane AI Plus
or Enterprise plan.
api_access: >-
A general "API access" capability is advertised only on the Enterprise
(contact-sales) tier at https://octaneai.com/pricing; no reference, base URL,
or authentication contract for it is published anywhere public.
rotation_and_scoping:
scopes: none-published
rotation: not-documented
note: >-
A single API key per account, no scoping model, no documented rotation or
revocation flow, and no documented signature algorithm for the webhook secret.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/octane-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.