Refersion · Authentication Profile
Refersion Authentication
Authentication
Refersion authenticates the REST API and the inbound order-tracking webhook with a static public/secret key PAIR sent as two custom request headers. There is no OAuth 2.0, no OpenID Connect, no bearer token, no mutual TLS and no token exchange of any kind. Note that the published OpenAPI declares NO `securitySchemes` and NO `security` block — the credentials are modelled as ordinary required header PARAMETERS, so automated tooling that reads only securitySchemes will conclude this API is unauthenticated. That is a real defect in the contract, not a gap in this profile.
Refersion declares 2 security scheme(s) across its OpenAPI definitions.
Affiliate MarketingInfluencer MarketingE-CommerceReferral TrackingCommission ManagementShopify
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
Refersion-Public-Key apiKey
Refersion-Secret-Key apiKey