Red Canary · Authentication Profile
Red Canary Authentication
Authentication
Red Canary secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.
CompanySecurityCybersecurityManaged Detection and ResponseThreat DetectionThreat IntelligenceEndpoint SecurityIncident ResponseSecurity OperationsAutomation
Methods: apiKey
Schemes: 1
OAuth flows:
API key in: header
Security Schemes
X-Api-Key apiKey
· in: header ()
Source
Authentication Profile
generated: '2026-08-05'
method: searched
source: openapi/ has no spec — derived from the provider's own published documentation
docs: https://docs.redcanary.com/docs/red-canary-rest-api
notes: >-
No OpenAPI document is publicly reachable, so this profile is read from Red Canary's
public REST API documentation and from its own first-party Python client
(https://github.com/redcanaryco/openapi), not from a securitySchemes block.
summary:
types:
- apiKey
api_key_in:
- header
oauth2_flows: []
schemes:
- name: X-Api-Key
type: apiKey
in: header
parameter_name: X-Api-Key
description: >-
Per-user API authentication token. Generated from the Red Canary portal under the
user profile -> Security Settings -> "Generate API Authentication Token". The token
inherits the roles/permissions of the user who created it, so API authorization is
role-based rather than scope-based.
sources:
- https://docs.redcanary.com/docs/red-canary-rest-api
- https://github.com/redcanaryco/openapi/blob/master/python/redcanary/rest.py
token_management:
scope: per-user
rotation: >-
Generating a new token revokes any existing token for that user. Red Canary advises
periodic rotation.
docs: https://docs.redcanary.com/docs/rest-api-faq
revocation: implicit on regeneration
tenancy:
model: subdomain
host_template: https://<subdomain>.my.redcanary.co/openapi/v3/
note: >-
Every API call is bound to the customer's own portal subdomain; there is no shared
global API host. https://go.my.redcanary.co/ is the subdomain selector / login gate.
portal_authentication:
note: >-
Human access to the portal (where the Swagger reference lives) is separate from API
token auth and supports SAML SSO and MFA.
sso:
- provider: Microsoft Entra ID
docs: https://docs.redcanary.com/docs/set-up-single-sign-on-to-microsoft-entra-id
- provider: Okta
docs: https://docs.redcanary.com/docs/set-up-single-sign-on-to-okta
- provider: OneLogin
docs: https://docs.redcanary.com/docs/set-up-single-sign-on-to-onelogin
- provider: Ping Identity
docs: https://docs.redcanary.com/docs/set-up-single-sign-on-to-ping-identity
mfa_docs: https://docs.redcanary.com/docs/configure-multi-factor-authentication-mfa
oauth:
present: false
note: >-
The REST API declares no OAuth 2.0 or OpenID Connect surface. No
/.well-known/oauth-authorization-server or /.well-known/openid-configuration is
served on any Red Canary host (all 404; see well-known/red-canary-well-known.yml).
scopes/ is therefore intentionally absent.
x-evidence:
fetched: '2026-08-05'
urls:
- url: https://docs.redcanary.com/docs/red-canary-rest-api.md
http_status: 200
- url: https://docs.redcanary.com/docs/rest-api-faq.md
http_status: 200
- url: https://raw.githubusercontent.com/redcanaryco/openapi/master/python/redcanary/rest.py
http_status: 200
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/red-canary-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.