Quaker Houghton · Authentication Profile

Quaker Houghton Authentication

Authentication

Authentication profile for every machine surface home.quakerhoughton.com publishes. Three distinct postures coexist on one host: anonymous keyless reads on the Events Calendar APIs, HTTP Basic (WordPress Application Passwords) on their writes, and OAuth 2.1 with PKCE on the MCP server. Quaker Houghton publishes no authentication documentation of its own — every fact here is read from a served contract or discovery document.

Quaker Houghton declares 4 security scheme(s) across its OpenAPI definitions.

Industrial FluidsChemicalsManufacturingMetalworkingLubricantsEventMCP
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

BasicAuth http
scheme: basic
anonymous none
QuakerHoughtonMCPOAuth oauth2
· flows: authorizationCode
WordPressSession cookie-or-basic

Source

Authentication Profile

quaker-houghton-authentication.yml Raw ↑
generated: '2026-09-17'
method: searched
source: >-
  openapi/_original/quaker-houghton-tec-v1-openapi-original.json (components.securitySchemes),
  openapi/_original/quaker-houghton-tribe-events-v1-openapi-original.json,
  https://home.quakerhoughton.com/.well-known/oauth-authorization-server,
  https://home.quakerhoughton.com/.well-known/oauth-protected-resource, and the
  WWW-Authenticate challenge observed on the MCP endpoint
docs: null
description: >-
  Authentication profile for every machine surface home.quakerhoughton.com publishes. Three
  distinct postures coexist on one host: anonymous keyless reads on the Events Calendar APIs,
  HTTP Basic (WordPress Application Passwords) on their writes, and OAuth 2.1 with PKCE on the
  MCP server. Quaker Houghton publishes no authentication documentation of its own — every
  fact here is read from a served contract or discovery document.
schemes:
- name: BasicAuth
  type: http
  scheme: basic
  surfaces: [tec/v1]
  applies_to: >-
    createEvent, updateEvent, deleteEvent, createOrganizer, updateOrganizer, deleteOrganizer,
    createVenue, updateVenue, deleteVenue (every write in tec/v1). Every read declares security: [].
  source: openapi/_original/quaker-houghton-tec-v1-openapi-original.json#/components/securitySchemes/BasicAuth
  credential: WordPress username + Application Password (the plugin's standard mechanism); no public signup exists.
- name: anonymous
  type: none
  surfaces: [tribe/events/v1 reads, tec/v1 reads]
  evidence: >-
    GET https://home.quakerhoughton.com/wp-json/tribe/events/v1/events answered HTTP 200 with no
    credentials on 2026-09-17 (total 0 events). The tribe/events/v1 document declares no
    securitySchemes at all; its POST/DELETE operations are enforced by WordPress capability checks
    (rest_forbidden 401) rather than a declared scheme.
- name: QuakerHoughtonMCPOAuth
  type: oauth2
  surfaces: [MCP server https://home.quakerhoughton.com/wp-json/mcp/mcp-oauth-server]
  flows:
  - flow: authorizationCode
    authorizationUrl: https://home.quakerhoughton.com/oauth/authorize
    tokenUrl: https://home.quakerhoughton.com/oauth/token
    refreshUrl: https://home.quakerhoughton.com/oauth/token
    revocationUrl: https://home.quakerhoughton.com/oauth/revoke
    pkce: required (S256)
    scopes:
      mcp: Access the MCP server
  bearer: header
  challenge: >-
    HTTP 401 with WWW-Authenticate: Bearer realm="https://home.quakerhoughton.com",
    resource_metadata="https://home.quakerhoughton.com/.well-known/oauth-protected-resource"
  client_registration: "client-ID metadata document (client_id_metadata_document_supported: true); no RFC 7591 endpoint"
  source: https://home.quakerhoughton.com/.well-known/oauth-authorization-server
  detail: scopes/quaker-houghton-scopes.yml
- name: WordPressSession
  type: cookie-or-basic
  surfaces: [https://home.quakerhoughton.com/wp-json/mcp/mcp-adapter-default-server, /wp-json/wp-abilities/v1/abilities]
  evidence: Anonymous requests answer 401 rest_forbidden with no OAuth challenge; standard WordPress REST authentication applies.
api_keys:
  issued: false
  note: No developer portal, signup or key-issuance flow exists anywhere on the Quaker Houghton estate.
x-evidence:
  fetched: '2026-09-17'
  probes:
  - url: https://home.quakerhoughton.com/wp-json/tribe/events/v1/events?per_page=2
    status: 200
  - url: https://home.quakerhoughton.com/wp-json/mcp/mcp-oauth-server
    status: 401
  - url: https://home.quakerhoughton.com/wp-json/mcp/mcp-adapter-default-server
    status: 401
  - url: https://home.quakerhoughton.com/wp-json/wp-abilities/v1/abilities
    status: 401

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/quaker-houghton-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.