Relm · Authentication Profile
Relmcrm Com Authentication
Authentication
Relm secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
CRMSalesContactsDealsSales PipelineAutomationWebhookMCPA2AAI AgentsAgent-NativeUnited Arab Emirates
Methods: http, oauth2
Schemes: 2
OAuth flows: authorizationCode
API key in:
Security Schemes
bearerAuth http
scheme: bearer
oauth2 oauth2
· flows: authorizationCode
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/relmcrm-com-openapi.yml (components.securitySchemes bearerAuth + oauth2; root security[]) + https://relmcrm.com/docs (Base URL & auth; Connect via MCP; OAuth 2.1) + https://relmcrm.com/security (Secrets and keys) + well-known/relmcrm-com-oauth-authorization-server.json + live probes 2026-09-19 (401 on GET https://api.relmcrm.com/v1/schema; JSON-RPC -32001 + WWW-Authenticate on anonymous MCP tools/call; failed Task on anonymous A2A message/send)
docs: https://relmcrm.com/docs
summary:
types:
- http
- oauth2
oauth2_flows:
- authorizationCode
one_credential_three_surfaces: The same bearer key (or OAuth access token) authenticates REST (https://api.relmcrm.com/v1), MCP (https://api.relmcrm.com/mcp) and A2A (https://api.relmcrm.com/a2a).
anonymous_surface: MCP initialize and tools/list, the OpenAPI, llms.txt, the agent card, the MCP descriptor and both OAuth discovery documents are public; every data operation requires a credential.
schemes:
- name: bearerAuth
type: http
scheme: bearer
header: 'Authorization: Bearer <key>'
key_prefixes:
live: relm_live_
test: relm_test_
minted_at: https://app.relmcrm.com/ (dashboard, "API keys" — live and test tabs)
shown_once: true
at_rest: SHA-256 hash; a lost key is rotated, never recovered (https://relmcrm.com/security)
scoping: workspace-bound; the key decides test vs live mode and data never crosses
recommended_for: servers and CI (docs); required for test mode
description: Workspace-scoped API key. relm_live_... (live) or relm_test_... (free, isolated test mode). Mint at https://app.relmcrm.com/.
failure: >-
401 application/problem+json code unauthorized — "Missing or invalid API key. Send `Authorization: Bearer
relm_live_...`." (observed live)
sources:
- openapi/relmcrm-com-openapi.yml
- https://relmcrm.com/docs
- name: oauth2
type: oauth2
version: OAuth 2.1
issuer: https://api.relmcrm.com
flows:
- flow: authorizationCode
authorizationUrl: https://api.relmcrm.com/oauth/authorize
tokenUrl: https://api.relmcrm.com/oauth/token
refreshUrl: https://api.relmcrm.com/oauth/token
scopes: 1
pkce: S256 required
refresh_tokens: yes, with rotation (docs)
dynamic_client_registration: RFC 7591 at https://api.relmcrm.com/oauth/register (POST; GET returns 404)
revocation: https://api.relmcrm.com/oauth/revoke
token_endpoint_auth_methods: [none, client_secret_post, client_secret_basic]
discovery:
authorization_server: https://api.relmcrm.com/.well-known/oauth-authorization-server (well-known/relmcrm-com-oauth-authorization-server.json)
protected_resource: https://api.relmcrm.com/.well-known/oauth-protected-resource (well-known/relmcrm-com-oauth-protected-resource.json)
live_only: true
live_only_note: OAuth grants act on live data; test mode stays API-key only (docs).
recommended_for: end-user chat clients (Claude, ChatGPT) — "the client registers itself, you approve in a browser, and you never handle a secret"
consent_screen: names the actual redirect destination and marks the app's self-declared name as unverified; anti-clickjacking protection; account creation and email confirmation inline (changelog v0.13.0–v0.15.0)
connected_apps: listed in the dashboard; disconnecting revokes all access immediately (changelog v0.17.0)
description: 'OAuth 2.1 with PKCE (S256) and dynamic client registration (RFC 7591). Live mode only; test mode is API-key only. Discovery: /.well-known/oauth-authorization-server.'
see: scopes/relmcrm-com-scopes.yml
sources:
- openapi/relmcrm-com-openapi.yml
- well-known/relmcrm-com-oauth-authorization-server.json
- https://relmcrm.com/docs
challenges_observed:
- surface: REST
request: GET https://api.relmcrm.com/v1/schema (no credential)
status: 401
body: application/problem+json type https://relmcrm.com/errors/unauthorized
www_authenticate: not present on the REST 401
- surface: MCP
request: POST https://api.relmcrm.com/mcp tools/call relm_describe_schema (no credential)
status: 401
body: >-
JSON-RPC error -32001 "Authorization required. Connect with OAuth, or send Authorization: Bearer relm_live_..."
www_authenticate: Bearer realm="Relm", resource_metadata="https://api.relmcrm.com/.well-known/oauth-protected-resource"
note: Also mirrored in error.data._meta["mcp/www_authenticate"]; this is the RFC 9728 §5.1 hop that lets an MCP client offer a Connect button.
- surface: A2A
request: POST https://api.relmcrm.com/a2a message/send (no credential)
status: 200
body: >-
terminal Task state failed; agent message text "Authentication required. Send Authorization: Bearer relm_live_...
(or relm_test_...)"; data part code unauthorized, auth bearer
mcp_security_schemes_per_tool: >-
every one of the 41 tools declares securitySchemes oauth2 with scopes [crm] (mcp/relmcrm-com-mcp-tools-list.json);
the bearer alternative is documented in /.well-known/mcp.json.
agent_card_security: >-
securitySchemes oauth2 (authorizationCode, scope crm) + bearer (http); security requires oauth2 [crm] OR bearer.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/relmcrm-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.