Quad/Graphics · Authentication Profile

Quad Graphics Authentication

Authentication

Quad/Graphics secures its APIs with openIdConnect across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, implicit, and hybrid flow(s).

MarketingPrintMediaAdvertisingDirect MailMarketing TechnologyRetail MediaPackagingData
Methods: openIdConnect Schemes: 1 OAuth flows: authorizationCode, implicit, hybrid API key in:

Security Schemes

quad-b2c-cloverleaf-production openIdConnect

Source

Authentication Profile

quad-graphics-authentication.yml Raw ↑
generated: '2026-08-13'
method: searched
source: >-
  https://quadb2c.b2clogin.com/quadb2c.onmicrosoft.com/B2C_1A_Cloverleaf_Production_SignUpOrSignIn/v2.0/.well-known/openid-configuration
docs: https://www.quad.com/solutions/technology/at-home-connect
note: >-
  Quad publishes no developer portal and no API reference, so there is no documented
  auth model for its APIs. What IS anonymously verifiable is the identity layer in
  front of the At-Home Connect self-service platform: the platform's SPA at
  athomeconnect.quad.com bootstraps against Microsoft Entra External ID (Azure AD B2C)
  in Quad's own `quadb2c.onmicrosoft.com` tenant, whose OIDC discovery document is
  public and was fetched (HTTP 200). The scheme below is read verbatim from that
  discovery document — it is the login for the product Quad markets as API-integrable,
  not a published API authentication contract. The postal API host
  (api.postal.quad.com) returns 403 to anonymous requests and publishes no
  WWW-Authenticate challenge, so its auth model could not be established.
summary:
  types: [openIdConnect]
  api_key_in: []
  oauth2_flows: [authorizationCode, implicit, hybrid]
  developer_facing_auth_documented: false
schemes:
  - name: quad-b2c-cloverleaf-production
    type: openIdConnect
    protocol: OpenID Connect 1.0 / OAuth 2.0
    provider: Microsoft Entra External ID (Azure AD B2C)
    tenant: quadb2c.onmicrosoft.com
    policy: B2C_1A_Cloverleaf_Production_SignUpOrSignIn
    applies_to: At-Home Connect (https://athomeconnect.quad.com/)
    issuer: https://quadb2c.b2clogin.com/d3a40049-07f8-47ef-93a3-3465ce8af90a/v2.0/
    openIdConnectUrl: >-
      https://quadb2c.b2clogin.com/quadb2c.onmicrosoft.com/B2C_1A_Cloverleaf_Production_SignUpOrSignIn/v2.0/.well-known/openid-configuration
    authorization_endpoint: >-
      https://quadb2c.b2clogin.com/quadb2c.onmicrosoft.com/b2c_1a_cloverleaf_production_signuporsignin/oauth2/v2.0/authorize
    token_endpoint: >-
      https://quadb2c.b2clogin.com/quadb2c.onmicrosoft.com/b2c_1a_cloverleaf_production_signuporsignin/oauth2/v2.0/token
    end_session_endpoint: >-
      https://quadb2c.b2clogin.com/quadb2c.onmicrosoft.com/b2c_1a_cloverleaf_production_signuporsignin/oauth2/v2.0/logout
    jwks_uri: >-
      https://quadb2c.b2clogin.com/quadb2c.onmicrosoft.com/b2c_1a_cloverleaf_production_signuporsignin/discovery/v2.0/keys
    response_types_supported:
      - code
      - code id_token
      - code token
      - code id_token token
      - id_token
      - id_token token
      - token
      - token id_token
    scopes_supported: [openid]
    subject_types_supported: [pairwise]
    id_token_signing_alg_values_supported: [RS256]
    claims_supported: [name, given_name, family_name, email, sub, tid, iss, iat, exp, aud, acr, nonce, auth_time]
    sources: [well-known/quad-graphics-b2c-openid-configuration.json]
unresolved:
  - host: https://api.postal.quad.com
    observed: HTTP 403 at /, HTTP 404 on unknown paths, no WWW-Authenticate header
    note: real Quad API host, but no anonymous auth discovery and no public reference
  - host: https://connect.qg.com
    observed: HTTP 401 on every path
    note: Client Connect customer portal; credentials required before anything is readable
x-evidence:
  - {url: 'https://quadb2c.b2clogin.com/quadb2c.onmicrosoft.com/B2C_1A_Cloverleaf_Production_SignUpOrSignIn/v2.0/.well-known/openid-configuration', status: 200, fetched: '2026-08-13'}
  - {url: 'https://athomeconnect.quad.com/', status: 200, fetched: '2026-08-13'}
  - {url: 'https://api.postal.quad.com/', status: 403, fetched: '2026-08-13'}
  - {url: 'https://connect.qg.com/openapi.json', status: 401, fetched: '2026-08-13'}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/quad-graphics-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.