Ploid · Authentication Profile
Ploid Authentication
Authentication
Ploid secures its APIs with apiKey, http, and oauth2 across 4 declared security schemes, as derived from its OpenAPI definitions.
CompanyPeople DataPeople SearchContact EnrichmentSales IntelligenceRecruitingLinkedInMCPAgentsData Enrichment
Methods: apiKey, http, oauth2
Schemes: 4
OAuth flows:
API key in: header
Security Schemes
bearerAuth http
scheme: bearer
apiKeyAuth apiKey
· in: header (x-api-key)
mcpOAuth oauth2
· flows:
deviceAuthorization oauth2
· flows:
Source
Authentication Profile
generated: '2026-10-07'
method: searched
source: openapi/ploid-openapi.yml
docs: https://ploid.com/documentation/getting-started/authentication
sources:
- openapi/ploid-openapi.yml
- https://ploid.com/documentation/getting-started/authentication
- https://ploid.com/documentation/mcp
- https://api.ploid.com/.well-known/oauth-authorization-server
- https://api.ploid.com/.well-known/oauth-protected-resource
- https://auth.ploid.com/.well-known/openid-configuration
summary:
types:
- apiKey
- http
- oauth2
api_key_in:
- header
note: >-
API requests authenticate with a Ploid API key sent either as Authorization: Bearer $PLOID_API_KEY or
as x-api-key: $PLOID_API_KEY; the organization and user identity are derived from the credential. Keys
are scoped (see scopes/), shown once (hashed storage), and can be revoked with DELETE /v1/account/key.
The hosted MCP server uses OAuth 2.1 (discovery, dynamic client registration, authorization code with
S256 PKCE, one-hour access tokens, rotating refresh tokens, revocation). The CLI and local MCP package
obtain a scoped key through a device authorization flow against auth.ploid.com.
schemes:
- name: bearerAuth
type: http
scheme: bearer
header: Authorization
format: 'Bearer $PLOID_API_KEY'
sources:
- openapi/ploid-openapi.yml
- https://ploid.com/documentation/getting-started/authentication
- name: apiKeyAuth
type: apiKey
in: header
parameter: x-api-key
sources:
- openapi/ploid-openapi.yml
- https://ploid.com/documentation/getting-started/authentication
- name: mcpOAuth
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://ploid.com/auth/mcp
tokenUrl: https://api.ploid.com/oauth/token
refreshUrl: https://api.ploid.com/oauth/token
scopes:
agent:chat: Use the harness context and chat completions
people:enrich: Enrich supported profile and contact fields
people:search: Search the public people index
account:read: Read usage and credits or revoke the caller key
pkce: S256
dynamic_client_registration: https://api.ploid.com/oauth/register
revocation: https://api.ploid.com/oauth/revoke
applies_to: https://api.ploid.com/mcp
sources:
- https://api.ploid.com/.well-known/oauth-authorization-server
- https://api.ploid.com/.well-known/oauth-protected-resource
- https://ploid.com/documentation/mcp
- name: deviceAuthorization
type: oauth2
flows:
deviceCode:
deviceAuthorizationUrl: https://auth.ploid.com/oauth2/device_authorization
tokenUrl: https://auth.ploid.com/oauth2/token
applies_to: 'ploid login and npx @ploid/mcp login (stores a narrowly scoped API key locally)'
issuer: https://auth.ploid.com
sources:
- https://auth.ploid.com/.well-known/openid-configuration
- https://ploid.com/documentation/getting-started/authentication
key_hygiene:
- Create a separate key for each environment or integration.
- Give it only the scopes the integration needs.
- Configure daily or monthly budgets where available.
- Never expose an API key in browser JavaScript. Send requests through your own server.
- Secrets are shown once; a lost secret must be revoked and replaced.
errors:
- code: missing_api_key
- code: invalid_api_key
- code: expired_api_key
- code: revoked_api_key
- code: insufficient_scope
status: 403
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ploid-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.