Ofcom · Authentication Profile
Ofcom Authentication
Authentication
Azure API Management subscription key, and nothing else. There is no OAuth, no OpenID Connect, no mTLS and no bearer-token option anywhere in Ofcom's surface — /.well-known/openid-configuration and /.well-known/oauth-authorization-server both return 404 on every Ofcom host. Keys are scoped to a PRODUCT, not to the provider: a Broadband key does not call the Mobile API. Issuance is self-serve to request but human-approved to grant.
Ofcom secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.
TelecommunicationsUnited KingdomRegulatorBroadbandMobile Network CoverageSpectrumOpen DataConnected Nations
Methods: apiKey
Schemes: 2
OAuth flows:
API key in: header, query
Security Schemes
apiKeyHeader apiKey
apiKeyQuery apiKey