RE/MAX · Authentication Profile

Re Max Authentication

Authentication

RE/MAX secures its APIs with oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

Real-EstateUnited StatesBrokerageProperty ListingsMLSRESOIDXPropTechFranchisingMortgageRentals
Methods: oauth2 Schemes: 3 OAuth flows: authorizationCode API key in:

Security Schemes

datahub-oauth2 oauth2
listings-oauth2-staging oauth2
wordpress-rest cookie-or-application-password

Source

Authentication Profile

Raw ↑
generated: '2026-07-26'
method: searched
source:
- collections/re-max-eu-datahub-api.postman_collection.json
- collections/re-max-eu-listings-api.postman_collection.json
- https://apidocs.datahub.remax.eu/
- live anonymous probes of the OAuth and API hosts, 2026-07-26
docs: https://apidocs.datahub.remax.eu/
summary:
  types:
  - oauth2
  oauth2_flows:
  - authorizationCode
  api_key_in: []
  bearer_tokens: false
  token_transport: query-parameter
  openid_connect_discovery: false
  scopes_published: false
  self_serve_credentials: false
note: >-
  RE/MAX has no single authentication model because it has no single API
  program. The two documented RE/MAX Europe APIs both use OAuth 2.0
  authorization code against RE/MAX Europe operated authorization servers, and
  both carry the resulting token as an access_token QUERY PARAMETER rather than
  an Authorization header. No OpenID Connect discovery document and no RFC 8414
  authorization-server metadata is served by either authorization server. No
  scope vocabulary is published; the Postman documentation ships the literal
  placeholder "<scope>". Credentials are not self-serve: the Datahub collection
  carries the client_id placeholder "Ask_REU" (ask RE/MAX Europe). Separately,
  the remax.eu WordPress estate answers anonymously for public read routes and
  returns 401 rest_forbidden for everything privileged, including its MCP and
  Abilities routes.
schemes:
- name: datahub-oauth2
  api: RE/MAX Europe Datahub API
  type: oauth2
  flow: authorizationCode
  authorizationUrl: https://oauth.datahub.remax.eu/authorize
  tokenUrl: https://oauth.datahub.remax.eu/token
  client_id_placeholder: Ask_REU
  scopes: []
  token_transport: access_token query parameter on every request
  sources:
  - collections/re-max-eu-datahub-api.postman_collection.json
  probes:
  - url: https://oauth.datahub.remax.eu/authorize
    status: 200
  - url: https://oauth.datahub.remax.eu/token
    status: 404
    note: 404 to an anonymous GET; the collection documents it as a POST token endpoint
  - url: https://oauth.datahub.remax.eu/.well-known/openid-configuration
    status: 404
  - url: https://oauth.datahub.remax.eu/.well-known/oauth-authorization-server
    status: 404
- name: listings-oauth2-staging
  api: RE/MAX Europe Listings API (staging)
  type: oauth2
  flow: authorizationCode
  authorizationUrl: https://oauth.pre-prod.remaxeu-datahub.bwscloud.tech/authorize
  tokenUrl: https://oauth.pre-prod.remaxeu-datahub.bwscloud.tech/token
  client_id_placeholder: <client-id>
  scopes: []
  token_transport: access_token query parameter on every request
  sources:
  - collections/re-max-eu-listings-api.postman_collection.json
  probes:
  - url: https://oauth.pre-prod.remaxeu-datahub.bwscloud.tech/.well-known/openid-configuration
    status: 403
    note: origin returns nginx 403 to all anonymous paths
- name: wordpress-rest
  api: RE/MAX Europe Site API (WordPress REST)
  type: cookie-or-application-password
  flow: null
  anonymous_read: true
  sources:
  - well-known/re-max-eu-wp-json.json
  probes:
  - url: https://www.remax.eu/wp-json/wp/v2/posts?per_page=1
    status: 200
    note: anonymous read of published content succeeds
  - url: https://www.remax.eu/wp-json/wp-abilities/v1/abilities
    status: 401
    body: '{"code":"rest_forbidden","message":"Sorry, you are not allowed to do that."}'
  - url: https://www.remax.eu/wp-json/mcp/mcp-adapter-default-server
    status: 401
    method_probed: 'POST tools/list'
enforcement_evidence:
- url: https://api.datahub.remax.eu/external/regions/
  status: 400
  body: '{"status":[{"code":4007,"message":"Login parameter Required"}],"result":{}}'
  finding: calling without an access_token is rejected
- url: https://api.datahub.remax.eu/external/regions/?access_token=invalidtoken123
  status: 403
  body: '{"status":[{"code":4004,"message":"Invalid or expired Session/Token"}],"result":{}}'
  finding: an invalid token is rejected; the gate is real and enforced
security_observations:
- >-
  Bearer material in the query string. Both RE/MAX Europe APIs pass the OAuth
  access token as a URL query parameter, so tokens land in server logs, proxy
  logs, referrer headers and browser history. An Authorization header is the
  RFC 6750 recommended transport.
- >-
  No authorization-server metadata. Neither OIDC discovery nor RFC 8414 metadata
  is served, so a client cannot machine-discover endpoints, supported grants,
  PKCE support or signing keys.
- >-
  No published scopes. Without a scope vocabulary, every issued credential is
  effectively coarse-grained from a consumer's point of view.
- >-
  The published staging Listings collection embedded a live-looking 128-character
  hexadecimal access_token in four request URLs; those values were redacted
  before this repo saved the file (see review.yml harvest.collections).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/re-max-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.