Rett fra Bonden · Authentication Profile
Rettfrabonden Com Authentication
Authentication
Rett fra Bonden secures its APIs with apiKey and none across 4 declared security schemes, as derived from its OpenAPI definitions.
Local FoodAgricultureFoodMarketplaceDirectorySearchGeolocationA2AMCPNorwayOpen SourceCompany
Methods: apiKey, none
Schemes: 4
OAuth flows:
API key in: header
Security Schemes
apiKey apiKey
· in: header (X-API-Key)
consumerApiKey apiKey
· in: header (X-API-Key)
adminKey apiKey
· in: header (X-Admin-Key)
none none
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/rettfrabonden-com-agent-surface-openapi.json
docs:
- https://rettfrabonden.com/llms.txt
- https://rettfrabonden.com/.well-known/agent-card.json
- https://rettfrabonden.com/.well-known/oauth-protected-resource
- https://rettfrabonden.com/teknologi
summary:
types: [apiKey, none]
api_key_in: [header]
oauth2_flows: []
model: >-
Reads are open. Every search/discover/detail/geocode/stats operation, the whole MCP tool surface
(including the anonymous cart flow) and the A2A message/send and tasks/* methods answer with no
credential. The ONE key-gated write is producer registration (POST /api/marketplace/register),
which requires an X-API-Key. A second, voluntary X-API-Key — the "consumer key" from POST /api/keys —
exists only to raise the caller's rate-limit ceiling and to attribute usage; it is not a login.
There is no OAuth, no OIDC and no bearer-token issuance: the RFC 9728 protected-resource document
declares authorization_servers [] and names the API key as the credential in vendor x-auth-* fields.
schemes:
- name: apiKey
type: apiKey
in: header
parameter: X-API-Key
role: producer key
required_for: [registerProducer, producer-side writes documented as "write operations"]
obtain: 'issued in the response to POST /api/marketplace/register (openapi.json: "Registered agent with API key"; protected-resource x-auth-obtain-url)'
scopes: [write]
sources: [a2a/rettfrabonden-com-agent-card.json, well-known/rettfrabonden-com-oauth-protected-resource.json, well-known/rettfrabonden-com-mcp-server-card.json]
description: API key received upon registration. Required for write operations; read/search operations are open.
- name: consumerApiKey
type: apiKey
in: header
parameter: X-API-Key
role: voluntary consumer-identity key for AI agents
required_for: []
obtain: POST https://rettfrabonden.com/api/keys with optional JSON body {label, contact_email}; the key is returned once and cannot be retrieved again
revoke: POST https://rettfrabonden.com/api/keys/revoke (stops the key, keeps history) or POST https://rettfrabonden.com/api/keys/erase (GDPR erasure of label/e-mail); both take {key} in the body or the key as X-API-Key
effect: about 3x higher rate-limit ceiling on the general REST and /a2a surface (300 -> 900 and 200 -> 600 per 15 minutes) and a per-key usage ledger (endpoint/tool name and date only); does NOT raise the static 150-per-15-minute quota on /api/marketplace/search and /discover
scopes: [read]
sources: [a2a/rettfrabonden-com-agent-card.json, llms/rettfrabonden-com-llms.txt]
description: Free, voluntary key — same header name as the producer key, different purpose; nothing requires it.
- name: adminKey
type: apiKey
in: header
parameter: X-Admin-Key
role: operator/admin key
required_for: [admin routes — not part of the public surface]
scopes: []
sources: [openapi/rettfrabonden-com-agent-surface-openapi.json]
description: >-
The only securityScheme declared in /openapi.json, and the scheme that spec attaches to registerProducer.
Every other provider document (agent card, protected-resource metadata, server card, /api index,
agents.txt) says registration is gated by X-API-Key, not X-Admin-Key. Recorded as spec drift; the
privacy page describes admin access as "protected with API keys in environment variables", i.e. an
operator credential.
- name: none
type: none
applies_to: [searchFood, searchProducers, discoverProducers, listProducers, getProducerInfo, getProducer, geocodePlace, getAcpProductFeed, getPlatformStats, getAgentCard, every MCP tool, A2A message/send, tasks/get, tasks/list]
sources: [openapi/rettfrabonden-com-openapi.yml, mcp/rettfrabonden-com-mcp-tools.json]
description: Anonymous access; rate-limited per IP (see rate-limits/).
observations:
- POST /api/marketplace/register with an empty JSON body and no key returned HTTP 400 with a zod validation error list, not 401 — input validation runs before (or instead of) the key check on an empty body, so which header actually gates a valid registration could not be observed without submitting a real registration, which this pass did not do.
- The card carries authentication {schemes:[apiKey]} (pre-0.3 shape) and security [] (no requirement) alongside its securitySchemes map.
- The site has no OpenID/OAuth discovery documents (/.well-known/openid-configuration and /oauth-authorization-server both 404) — scopes_supported [read, write] in the protected-resource document are API-key scopes, not OAuth scopes, so no scopes/ artifact is emitted.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rettfrabonden-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.