Posh · Authentication Profile
Posh Authentication
Authentication
Posh declares 0 security scheme(s) across its OpenAPI definitions.
Artificial IntelligenceConversational AIAgentic AIBankingCredit UnionsFinancial-ServicesCustomer ServiceContact CenterVoiceChatbotsKnowledge-ManagementRegTech
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-08-26'
method: probed
source: 'live probes of https://api.poshdevelopment.com + https://app.poshdevelopment.com + https://security.posh.ai'
note: >-
No OpenAPI securitySchemes exist to derive from — Posh publishes no contract — so this profile
is built only from observed gateway behaviour and Posh's own security claims. The scheme name,
header and token format are NOT recorded because they were not observable, and inventing them
would be worse than an honest gap.
public_documentation: false
schemes: []
observed:
- surface: https://api.poshdevelopment.com/api-docs
http_status: 403
body: 'RBAC: access denied'
content_type: text/plain
finding: >-
The gateway enforces role-based access control at the edge, ahead of the application error
handler. This is a positive signal that authorization is centrally enforced, and it is the
wall that makes the API reference unreadable to the public.
- surface: https://app.poshdevelopment.com/login
http_status: 200
finding: >-
The Posh Portal is a browser SPA behind a login form. No OIDC discovery document is served
(/.well-known/openid-configuration returns the SPA shell, not a document), so the identity
provider could not be identified.
- surface: https://api.poshdevelopment.com/.well-known/oauth-authorization-server
http_status: 404
finding: 'No RFC 8414 authorization-server metadata.'
- surface: https://api.poshdevelopment.com/.well-known/openid-configuration
http_status: 404
finding: 'No OIDC discovery.'
provider_claims:
- claim: multi-factor authentication
source: https://security.posh.ai/
- claim: role-based access control
source: https://security.posh.ai/
- claim: voice-based biometric authentication, opt-in consent only
source: https://www.posh.ai/security-privacy-policy
- claim: 'multi-factor authentication and core system integration in the Voice Assistant'
source: https://www.posh.ai/llms.txt
embedded_surface_auth:
component: Posh Answers web embed
mechanism: 'Two opaque public identifiers passed as script-tag data attributes: data-org_id and data-user_key.'
source: https://poshie-chat-api.poshdevelopment.com/entry-answers.js
note: >-
Read from the shipped loader, not from documentation. Both values are also accepted as URL
query parameters (posh_org_id, posh_user_key), which means they are public, page-embedded
identifiers rather than secrets. They scope the embed to a tenant; they are not API
credentials and must not be treated as such.
gaps:
- no public authentication documentation
- no OIDC or OAuth discovery document on any host
- token format, header name and credential lifecycle all unknown to the public
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/posh-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.