Poptin · Authentication Profile

Poptin Authentication

Authentication

Poptin declares 2 security scheme(s) across its OpenAPI definitions.

CompanyMarketingEmail MarketingMarketing AutomationLead GenerationConversion OptimizationFormsPopupsContact ManagementWebhookE-CommerceSoftware-as-a-Service
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

Make/Zapier API key apiKey
Application session login http

Source

Authentication Profile

poptin-authentication.yml Raw ↑
generated: '2026-08-12'
method: searched
source: https://help.poptin.com/en/article/how-to-integrate-your-poptin-to-make-etfiwq/
sources:
- https://help.poptin.com/en/article/how-to-integrate-your-poptin-to-make-etfiwq/
- https://help.poptin.com/en/article/how-to-integrate-your-poptin-to-zapier-9exnpm/
- https://app.popt.in/login
note: >-
  Derived-from-OpenAPI was not possible: Poptin publishes no OpenAPI, no Swagger, no
  GraphQL SDL and no API reference of any kind (see well-known/poptin-well-known.yml and
  the x-coverage block in apis.yml). This profile is what the provider actually documents
  plus one anonymous live probe. Nothing about token format, header name, expiry, scopes
  or refresh is published by Poptin, so nothing about them is asserted here.
openapi_security_schemes: []
schemes:
- id: make-zapier-api-key
  type: apiKey
  name: Make/Zapier API key
  issued_from: Poptin dashboard > Settings > Profile
  used_by:
  - Make (make.com) connector
  - Zapier connector
  transport: not documented
  header_name: not documented
  rotation: not documented
  expiry: not documented
  scopes: none published
  documented_reference: false
  note: >-
    Poptin's help center tells a user where to COPY this key, and nothing else. No base
    URL, no endpoint, no header name, no example request is published alongside it.
- id: session-login
  type: http
  name: Application session login
  url: https://app.popt.in/login
  note: >-
    Human sign-in to the Poptin application. Registration at https://app.popt.in/register.
    Not an API credential.
oauth2:
  supported: false
  note: >-
    No OAuth authorization or token endpoint is published by Poptin, and
    /.well-known/oauth-authorization-server returns 404 on both hosts. Third-party
    integration-guide sites assert an OAuth flow at api.poptin.com — that hostname does
    not resolve in DNS, so those claims are not carried into this catalog.
scopes_artifact: not applicable — no OAuth surface
live_probe:
  url: https://app.popt.in/api/display/limitLogs/
  method: GET
  status: 401
  content_type: application/json
  fetched: '2026-08-12'
  interpretation: >-
    The application host does enforce authentication on its internal /api/ surface and
    answers with JSON, which confirms a real authenticated API exists. What it does not
    do is document it.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/poptin-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.