Ramp Network · Authentication Profile

Ramp Network Authentication

Authentication

Ramp Network declares 3 security scheme(s) across its OpenAPI definitions.

CryptocurrencyPaymentsFintechOn-RampOff-RampBlockchainWeb3WalletsDigital AssetsComplianceEmbedded Finance
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

hostApiKey apiKey
· in: query ()
secret apiKey
· in: query ()
signature

Source

Authentication Profile

ramp-network-authentication.yml Raw ↑
generated: '2026-08-26'
method: searched
source: https://docs.rampnetwork.com/api-keys
docs: https://docs.rampnetwork.com/api-keys
summary: >-
  Ramp Network has no OAuth surface and no bearer-token API. The public Host API is
  largely ANONYMOUS — assets, prices, currencies, payment methods and payout methods
  are readable with no credential at all (verified live on 2026-08-26 against
  https://api.rampnetwork.com/api/host-api/v3/currencies, HTTP 200). Three distinct
  credential mechanisms exist on top of that, and they are not interchangeable.
schemes:
  - id: hostApiKey
    type: apiKey
    in: query
    name: hostApiKey
    required: conditional
    applies_to:
      - GET /host-api/v3/assets
      - GET /host-api/v3/offramp/assets
      - POST /host-api/v3/onramp/quote/all
      - POST /host-api/v3/offramp/quote/all
      - Ramp Instant SDK / widget initialisation
      - Hosted widget URL (https://app.rampnetwork.com/?hostApiKey=...)
    description: >-
      The integration (partner) key. Issued by Ramp Network on request — there is no
      self-service key issuance. On the assets endpoints it is optional and unlocks
      an `enabledFeatures` list plus partner-specific configuration; on the quote
      endpoints the docs present it as the required identifier. It is also the key
      that attributes purchases to a partner integration for revenue share. Because
      it travels in the QUERY STRING and is embedded in client-side widget
      initialisation, it is a partner identifier rather than a secret.
    obtain: https://docs.rampnetwork.com/api-keys
    contact: partner@ramp.network
  - id: purchaseViewToken
    type: apiKey
    in: query
    name: secret
    required: true
    applies_to:
      - GET /host-api/purchase/{id}
      - GET /host-api/offramp/sale/{id}
    description: >-
      A per-transaction capability token (`purchaseViewToken` / `saleViewToken`)
      delivered with the PURCHASE_CREATED / OFFRAMP_SALE_CREATED SDK event and the
      corresponding webhook. It is passed as the `secret` query parameter and scopes
      read access to exactly one transaction. This is an object-capability model,
      not an account credential — possession of the token is the authorisation.
  - id: webhook-signature
    type: signature
    direction: inbound-to-integrator
    header: X-Body-Signature
    algorithm: ECDSA over secp256k1 with SHA-256, DER signature, base64 encoded
    canonicalisation: >-
      JSON request body serialised with fast-json-stable-stringify (object keys
      sorted alphabetically, no whitespace)
    key_distribution: public keys published verbatim in the webhook documentation (separate production and demo keys)
    description: >-
      Ramp Network signs every outbound webhook call so the integrator can verify
      authenticity. This is the only cryptographic authentication in the surface,
      and it authenticates RAMP TO THE INTEGRATOR, not the other way round.
    docs: https://docs.rampnetwork.com/webhooks
oauth2: false
openid_connect: false
mutual_tls: false
gaps:
  - >-
    No OAuth 2.0, no OpenID Connect, no scope model — so scopes/ is intentionally
    not emitted for this provider.
  - >-
    hostApiKey is transmitted as a URL query parameter and is present in
    client-side widget configuration, so it will appear in browser history, proxy
    logs and referrer headers. The docs do not describe rotation or revocation.
  - >-
    No published authentication error catalogue; failures surface through the
    generic `{ code, statusCode }` error envelope.
evidence:
  - url: https://docs.rampnetwork.com/api-keys
    status: 200
  - url: https://docs.rampnetwork.com/webhooks
    status: 200
  - url: https://api.rampnetwork.com/api/host-api/v3/currencies
    status: 200
    detail: returned the full currency list with no credential supplied

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ramp-network-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.