RealScout · Authentication Profile

Realscout Authentication

Authentication

RealScout secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyEnterpriseReal-EstatePropTechLead NurtureHome SearchMLSMCPArtificial Intelligence
Methods: oauth2 Schemes: 1 OAuth flows: authorizationCode API key in:

Security Schemes

OAuth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

realscout-authentication.yml Raw ↑
generated: '2026-07-20'
method: searched
source: https://www.realscout.com/.well-known/oauth-authorization-server
docs: https://www.realscout.com/.well-known/oauth-authorization-server
summary:
  types: [oauth2]
  oauth2_flows: [authorizationCode]
  pkce: S256
  dynamic_client_registration: true
schemes:
  - name: OAuth2
    type: oauth2
    flows:
      - flow: authorizationCode
        issuer: https://www.realscout.com
        authorizationUrl: https://www.realscout.com/oauth/authorize
        tokenUrl: https://www.realscout.com/oauth/token
        registrationUrl: https://www.realscout.com/oauth/register   # RFC 7591
        revocationUrl: https://www.realscout.com/oauth/revoke        # RFC 7009
        jwksUri: https://www.realscout.com/.well-known/mcp/jwks.json
        scopes:
          mcp: Access to the RealScout admin MCP server (api://realscout-admin-mcp)
        code_challenge_methods_supported: [S256]
        token_endpoint_auth_methods_supported: [none]   # public clients (PKCE)
        response_types_supported: [code]
        grant_types_supported: [authorization_code, refresh_token]
        sources: [well-known/realscout-oauth-authorization-server.json]
notes: >-
  Auth model derived from RealScout's live RFC 8414 authorization-server metadata,
  which backs the hosted MCP server. This OAuth 2.1 surface is the only publicly
  documented authentication. RealScout also advertises "direct API access" and
  "SAML / SSO" on Enterprise plans (learn.realscout.com/pricing), but no public
  OpenAPI or developer auth docs are published for that API.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/realscout-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.