Ofcom · Authentication Profile
Ofcom Authentication
Authentication
Azure API Management subscription key, and nothing else. There is no OAuth, no OpenID Connect, no mTLS and no bearer-token option anywhere in Ofcom's surface — /.well-known/openid-configuration and /.well-known/oauth-authorization-server both return 404 on every Ofcom host. Keys are scoped to a PRODUCT, not to the provider: a Broadband key does not call the Mobile API. Issuance is self-serve to request but human-approved to grant.
Ofcom secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.
TelecommunicationsUnited KingdomRegulatorBroadbandMobile Network CoverageSpectrumOpen DataConnected Nations
Methods: apiKey
Schemes: 2
OAuth flows:
API key in: header, query
Security Schemes
apiKeyHeader apiKey
apiKeyQuery apiKey
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.