Odaseva · Authentication Profile

Odaseva Authentication

Authentication

Odaseva secures its APIs with oauth2 and password-login across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and refreshToken flow(s).

CompanyInfrastructure SaasSalesforceData ProtectionBackupData GovernanceSecurityCompliancePrivacy
Methods: oauth2, password-login Schemes: 2 OAuth flows: authorizationCode, refreshToken API key in:

Security Schemes

SalesforcePlatformOIDC openIdConnect
OdasevaCliLogin http
scheme: password-then-bearer-token

Source

Authentication Profile

odaseva-authentication.yml Raw ↑
generated: '2026-08-17'
method: probed
source: >-
  Live probes of api.odaseva.com and platform.odaseva.com plus the first-party
  odaseva-cli@2022.12.0 npm release; no OpenAPI exists to derive from
  (derive-authentication.py found 0 auth profiles for this provider).
pointer_note: >-
  DELIBERATELY NOT WIRED as a `type: Authentication` pointer in apis.yml. Odaseva publishes
  NO public authentication documentation — this file is our probe record, not a provider
  document, and emitting the pointer would credit Odaseva with a documented auth surface it
  does not publish. Re-evaluate if Odaseva ever puts an auth page or spec on a public URL.
summary:
  types:
  - oauth2
  - password-login
  api_key_in: []
  oauth2_flows:
  - authorizationCode
  - refreshToken
  identity_provider: Salesforce (login.salesforce.com)
  public_docs: false
hosts:
- host: api.odaseva.com
  role: Odaseva Platform API host (Salesforce My Domain, Visualforce /CBR/ namespace)
  unauthenticated_response: 401 on every probed API and .well-known path except OIDC discovery
  ip_space: Salesforce (155.226.157.0/24)
- host: platform.odaseva.com
  role: Odaseva Console / platform login (https://platform.odaseva.com/CBR, HTTP 200)
  unauthenticated_response: 301 at root, 401 on API paths
schemes:
- name: SalesforcePlatformOIDC
  type: openIdConnect
  owner: salesforce
  openIdConnectUrl: https://api.odaseva.com/.well-known/openid-configuration
  issuer: https://login.salesforce.com
  authorizationUrl: https://login.salesforce.com/services/oauth2/authorize
  tokenUrl: https://login.salesforce.com/services/oauth2/token
  revocationUrl: https://login.salesforce.com/services/oauth2/revoke
  introspectionUrl: https://login.salesforce.com/services/oauth2/introspect
  userinfoUrl: https://login.salesforce.com/services/oauth2/userinfo
  jwksUri: https://login.salesforce.com/id/keys
  id_token_signing_alg_values_supported:
  - RS256
  dpop: true
  sources:
  - well-known/odaseva-api-openid-configuration.json
  note: >-
    OWNERSHIP: this discovery document is Salesforce's, served from Odaseva's Salesforce My
    Domain hosts. It describes the Salesforce platform authorization server, and its
    scopes (api, full, refresh_token, offline_access, cdp_*, mcp_api, ...) are Salesforce
    platform scopes — NOT Odaseva-defined scopes. It is recorded because it is the real,
    observable way the Odaseva platform host authenticates callers, and it is the reason
    no scopes/ artifact is written: Odaseva publishes no scope vocabulary of its own.
- name: OdasevaCliLogin
  type: http
  scheme: password-then-bearer-token
  owner: odaseva
  credentials:
  - Odaseva username
  - Odaseva password
  - Odaseva Org Id
  - Odaseva endpoint alias
  token: access token (stored in ~/.odaseva_cli; "Session expired!" on expiry)
  sources:
  - packages/odaseva-packages.yml
  - cli/odaseva-cli.yml
  note: >-
    Strings read verbatim out of the published odaseva-cli binary: "Odaseva username",
    "Odaseva password", "Access token", "Odaseva Org Id", "Odaseva endpoint alias",
    "User successfully logged in.", "Session expired!", "The password is expired. Login
    failed." No API-key mechanism appears anywhere in the published surface.
evidence:
- url: https://api.odaseva.com/.well-known/openid-configuration
  status: 200
- url: https://api.odaseva.com/openapi.json
  status: 401
- url: https://platform.odaseva.com/.well-known/openid-configuration
  status: 200
- url: https://platform.odaseva.com/CBR
  status: 200
gaps:
- No public authentication documentation page.
- No published OpenAPI securitySchemes (no spec at all).
- No Odaseva-defined OAuth scopes; the visible scope set belongs to the Salesforce platform.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/odaseva-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.