Qogita · Authentication Profile

Qogita Authentication

Authentication

Qogita secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyEcommerceWholesaleMarketplaceHealth and BeautyB2BRetailDistribution
Methods: oauth2 Schemes: 1 OAuth flows: authorizationCode API key in:

Security Schemes

OAuth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

qogita-authentication.yml Raw ↑
generated: '2026-07-20'
method: searched
source: >-
  https://api.qogita.com/.well-known/oauth-authorization-server +
  https://api.qogita.com/.well-known/openid-configuration
summary:
  types: [oauth2]
  oauth2_flows: [authorizationCode]
  pkce: S256
  token_endpoint_auth_methods: [client_secret_basic, client_secret_post, none]
schemes:
- name: OAuth2
  type: oauth2
  description: >-
    OAuth 2.1 authorization-code flow with PKCE (S256) protecting the Qogita
    hosted MCP resource, advertised via RFC 8414 authorization-server metadata
    and RFC 9728 protected-resource metadata.
  issuer: https://api.qogita.com
  flows:
  - flow: authorizationCode
    authorizationUrl: https://api.qogita.com/staff/oauth/authorize
    tokenUrl: https://api.qogita.com/staff/oauth/token
    registrationUrl: https://api.qogita.com/staff/oauth/register
    grant_types: [authorization_code, refresh_token]
    code_challenge_methods: [S256]
    scopes:
      staff:mcp: Access to the Qogita Staff MCP server
  sources:
  - well-known/qogita-oauth-authorization-server.json
notes: >-
  Auth profile derived from the published OAuth/OIDC discovery documents rather
  than an OpenAPI spec (Qogita's REST API reference is a hosted Notion portal
  with no downloadable OpenAPI). The buyer-facing REST API on api.qogita.com is
  documented at developers.qogita.com; its auth scheme is not machine-readable
  here and is therefore not asserted.