Offerpad · Authentication Profile

Offerpad Authentication

Authentication

Offerpad secures its APIs with http, oauth2, and openIdConnect across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

Real-EstateUnited StatesiBuyerPropTechProperty ListingsBrokerageMLSCash OfferRenovationHome Buying
Methods: http, oauth2, openIdConnect Schemes: 3 OAuth flows: authorizationCode API key in:

Security Schemes

applicationPasswords http
scheme: basic
offerpadHelixOAuth oauth2
· flows: authorizationCode
offerpadOkta openIdConnect

Source

Authentication Profile

Raw ↑
generated: '2026-07-26'
method: searched
source: >-
  Live probes: https://www.offerpad.com/wp-json/ discovery document,
  https://helix.offerpad.com/.well-known/oauth-authorization-server,
  https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/.well-known/openid-configuration,
  and openapi/offerpad-wordpress-wp-v2-openapi.yml
summary:
  types:
    - http
    - oauth2
    - openIdConnect
  api_key_in: []
  oauth2_flows:
    - authorizationCode
  self_serve: false
  note: >-
    Offerpad publishes no developer authentication documentation, no API key programme and
    no client registration path. Both auth surfaces below were discovered by probing, not
    from developer docs. Neither grants access to any real estate, listing, valuation or
    transaction capability on a self-serve basis.
schemes:
  - name: applicationPasswords
    type: http
    scheme: basic
    surface: Offerpad WordPress REST API
    sources:
      - openapi/offerpad-wordpress-wp-v2-openapi.yml
      - openapi/offerpad-wp-json-discovery.json
    description: >-
      WordPress application passwords, advertised in the wp-json discovery document under
      authentication.application-passwords. Credentials are issued interactively at
      https://www.offerpad.com/wp-admin/authorize-application.php and sent as HTTP Basic.
      Required for every write route and for reads in the edit context; anonymous callers
      get the view context only. Issuance requires an Offerpad WordPress account — there is
      no self-serve signup, so this is effectively staff-only.
    authorization_endpoint: https://www.offerpad.com/wp-admin/authorize-application.php
    anonymous_read: true
    evidence:
      - {source: 'https://www.offerpad.com/wp-json/', status: 200, finding: 'authentication.application-passwords.endpoints.authorization present'}
      - {source: 'https://www.offerpad.com/wp-json/wp/v2/settings', status: 401, finding: '{"code":"rest_forbidden","message":"Sorry, you are not allowed to do that.","data":{"status":401}}'}
  - name: offerpadHelixOAuth
    type: oauth2
    surface: Offerpad Helix customer backend (private)
    sources:
      - well-known/offerpad-helix-oauth-authorization-server.json
    description: >-
      The private customer backend at https://helix.offerpad.com serves an RFC 8414
      authorization-server metadata document anonymously. It delegates to an Okta custom
      authorization server. Public clients (the Offerpad Connect SPA and the Offerpad mobile
      apps) use authorization code with S256 PKCE; there is no public client registration,
      so third parties cannot obtain a client_id.
    flows:
      - flow: authorizationCode
        issuer: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357
        authorizationUrl: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/authorize
        tokenUrl: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/token
        scopes:
          openid: Issue an OpenID Connect ID token for the signed-in Offerpad customer.
          profile: Basic profile claims for the signed-in customer.
          email: Email address and verification status for the signed-in customer.
    grant_types_supported:
      - authorization_code
      - refresh_token
    code_challenge_methods_supported:
      - S256
    token_endpoint_auth_methods_supported:
      - client_secret_post
      - client_secret_basic
    evidence:
      - {source: 'https://helix.offerpad.com/.well-known/oauth-authorization-server', status: 200}
  - name: offerpadOkta
    type: openIdConnect
    surface: Offerpad customer identity (Okta)
    openIdConnectUrl: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/.well-known/openid-configuration
    sources:
      - well-known/offerpad-okta-openid-configuration.json
      - well-known/offerpad-okta-org-openid-configuration.json
    description: >-
      Full OpenID Connect Discovery 1.0 metadata, served anonymously. Endpoints: authorize,
      token, userinfo, jwks, introspect, revoke, end_session, device authorize, and pushed
      authorization requests (PAR). ID tokens are RS256 signed; DPoP signing algorithms are
      advertised. 32 standard claims are supported. The Okta org-level issuer
      (https://offerpad.okta.com) is also discoverable and adds a groups scope.
    endpoints:
      authorization: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/authorize
      token: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/token
      userinfo: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/userinfo
      jwks: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/keys
      introspection: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/introspect
      revocation: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/revoke
      end_session: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/logout
      device_authorization: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/device/authorize
      pushed_authorization_request: https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/v1/par
      registration: https://offerpad.okta.com/oauth2/v1/clients
    id_token_signing_alg_values_supported:
      - RS256
    dpop_signing_alg_values_supported:
      - RS256
      - RS384
      - RS512
      - ES256
      - ES384
      - ES512
    evidence:
      - {source: 'https://offerpad.okta.com/oauth2/ausftur6n2aTu6Sur357/.well-known/openid-configuration', status: 200}
      - {source: 'https://offerpad.okta.com/.well-known/openid-configuration', status: 200}
not_found:
  - api_keys: No API key programme, key management console or key documentation exists on any Offerpad host.
  - mutual_tls: No mTLS surface advertised.
  - partner_auth: >-
      The Direct+, Powered By Offerpad, homebuilder and vendor partner programmes are gated
      behind intake forms and an NDA; no programmatic credential is described anywhere.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/offerpad-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.