Relm · Authentication Profile

Relmcrm Com Authentication

Authentication

Relm secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CRMSalesContactsDealsSales PipelineAutomationWebhookMCPA2AAI AgentsAgent-NativeUnited Arab Emirates
Methods: http, oauth2 Schemes: 2 OAuth flows: authorizationCode API key in:

Security Schemes

bearerAuth http
scheme: bearer
oauth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/relmcrm-com-openapi.yml (components.securitySchemes bearerAuth + oauth2; root security[]) + https://relmcrm.com/docs (Base URL & auth; Connect via MCP; OAuth 2.1) + https://relmcrm.com/security (Secrets and keys) + well-known/relmcrm-com-oauth-authorization-server.json + live probes 2026-09-19 (401 on GET https://api.relmcrm.com/v1/schema; JSON-RPC -32001 + WWW-Authenticate on anonymous MCP tools/call; failed Task on anonymous A2A message/send)
docs: https://relmcrm.com/docs
summary:
  types:
  - http
  - oauth2
  oauth2_flows:
  - authorizationCode
  one_credential_three_surfaces: The same bearer key (or OAuth access token) authenticates REST (https://api.relmcrm.com/v1), MCP (https://api.relmcrm.com/mcp) and A2A (https://api.relmcrm.com/a2a).
  anonymous_surface: MCP initialize and tools/list, the OpenAPI, llms.txt, the agent card, the MCP descriptor and both OAuth discovery documents are public; every data operation requires a credential.
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  header: 'Authorization: Bearer <key>'
  key_prefixes:
    live: relm_live_
    test: relm_test_
  minted_at: https://app.relmcrm.com/ (dashboard, "API keys" — live and test tabs)
  shown_once: true
  at_rest: SHA-256 hash; a lost key is rotated, never recovered (https://relmcrm.com/security)
  scoping: workspace-bound; the key decides test vs live mode and data never crosses
  recommended_for: servers and CI (docs); required for test mode
  description: Workspace-scoped API key. relm_live_... (live) or relm_test_... (free, isolated test mode). Mint at https://app.relmcrm.com/.
  failure: >-
    401 application/problem+json code unauthorized — "Missing or invalid API key. Send `Authorization: Bearer
    relm_live_...`." (observed live)
  sources:
  - openapi/relmcrm-com-openapi.yml
  - https://relmcrm.com/docs
- name: oauth2
  type: oauth2
  version: OAuth 2.1
  issuer: https://api.relmcrm.com
  flows:
  - flow: authorizationCode
    authorizationUrl: https://api.relmcrm.com/oauth/authorize
    tokenUrl: https://api.relmcrm.com/oauth/token
    refreshUrl: https://api.relmcrm.com/oauth/token
    scopes: 1
  pkce: S256 required
  refresh_tokens: yes, with rotation (docs)
  dynamic_client_registration: RFC 7591 at https://api.relmcrm.com/oauth/register (POST; GET returns 404)
  revocation: https://api.relmcrm.com/oauth/revoke
  token_endpoint_auth_methods: [none, client_secret_post, client_secret_basic]
  discovery:
    authorization_server: https://api.relmcrm.com/.well-known/oauth-authorization-server (well-known/relmcrm-com-oauth-authorization-server.json)
    protected_resource: https://api.relmcrm.com/.well-known/oauth-protected-resource (well-known/relmcrm-com-oauth-protected-resource.json)
  live_only: true
  live_only_note: OAuth grants act on live data; test mode stays API-key only (docs).
  recommended_for: end-user chat clients (Claude, ChatGPT) — "the client registers itself, you approve in a browser, and you never handle a secret"
  consent_screen: names the actual redirect destination and marks the app's self-declared name as unverified; anti-clickjacking protection; account creation and email confirmation inline (changelog v0.13.0–v0.15.0)
  connected_apps: listed in the dashboard; disconnecting revokes all access immediately (changelog v0.17.0)
  description: 'OAuth 2.1 with PKCE (S256) and dynamic client registration (RFC 7591). Live mode only; test mode is API-key only. Discovery: /.well-known/oauth-authorization-server.'
  see: scopes/relmcrm-com-scopes.yml
  sources:
  - openapi/relmcrm-com-openapi.yml
  - well-known/relmcrm-com-oauth-authorization-server.json
  - https://relmcrm.com/docs
challenges_observed:
- surface: REST
  request: GET https://api.relmcrm.com/v1/schema (no credential)
  status: 401
  body: application/problem+json type https://relmcrm.com/errors/unauthorized
  www_authenticate: not present on the REST 401
- surface: MCP
  request: POST https://api.relmcrm.com/mcp tools/call relm_describe_schema (no credential)
  status: 401
  body: >-
    JSON-RPC error -32001 "Authorization required. Connect with OAuth, or send Authorization: Bearer relm_live_..."
  www_authenticate: Bearer realm="Relm", resource_metadata="https://api.relmcrm.com/.well-known/oauth-protected-resource"
  note: Also mirrored in error.data._meta["mcp/www_authenticate"]; this is the RFC 9728 §5.1 hop that lets an MCP client offer a Connect button.
- surface: A2A
  request: POST https://api.relmcrm.com/a2a message/send (no credential)
  status: 200
  body: >-
    terminal Task state failed; agent message text "Authentication required. Send Authorization: Bearer relm_live_...
    (or relm_test_...)"; data part code unauthorized, auth bearer
mcp_security_schemes_per_tool: >-
  every one of the 41 tools declares securitySchemes oauth2 with scopes [crm] (mcp/relmcrm-com-mcp-tools-list.json);
  the bearer alternative is documented in /.well-known/mcp.json.
agent_card_security: >-
  securitySchemes oauth2 (authorizationCode, scope crm) + bearer (http); security requires oauth2 [crm] OR bearer.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/relmcrm-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.