Salsify · Authentication Profile

Salsify Authentication

Authentication

Salsify secures its APIs with apiKey and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyProduct Experience ManagementProduct Information ManagementDigital Asset ManagementCommerceRetailSyndicationData ManagementSoftware-as-a-Service
Methods: apiKey, oauth2 Schemes: 2 OAuth flows: authorizationCode API key in: header, query

Security Schemes

sec0 apiKey
· in: header (Authorization)
OAuth2 (documented, not declared in OpenAPI) oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-08-02'
method: searched
source: openapi/salsify-api-settings-openapi.json, openapi/salsify-non-v1-endpoints-openapi.json,
  openapi/salsify-write-operations-openapi.json
docs: https://developers.salsify.com/docs/authentication-model
summary:
  types:
  - apiKey
  - oauth2
  api_key_in:
  - header
  - query
  oauth2_flows:
  - authorizationCode
models:
- id: session
  name: Session
  applies_to: Interactive browser use only
  description: >-
    Username/password or SAML 2.0 SSO login stores a session cookie that expires after
    one week, or after 24 hours of inactivity. Login is CAPTCHA-protected specifically
    to prevent non-interactive session establishment.
  rate_limit: 5,000 requests per hour, per user
  docs: https://developers.salsify.com/docs/authentication-model
- id: api-key
  name: API Key
  applies_to: Programmatic REST and GraphQL access
  description: >-
    Every Salsify user has an associated API key generated on the My Profile page
    (https://app.salsify.com/app/profile/edit/api). Sent as the Authorization request
    header; also accepted as an access_token query parameter. The key inherits all of
    that user's permissions and does not expire unless regenerated. Salsify recommends
    a dedicated least-privilege integration user rather than a human account.
  rate_limit: 10,000 requests per hour, per organization
  docs: https://developers.salsify.com/reference/token-authentication-via-header-parameter
- id: oauth2
  name: OAuth 2.0
  applies_to: Multi-tenant integrations acting on behalf of Salsify users
  description: >-
    Salsify is an OAuth 2.0 provider supporting only the Authorization Code grant.
    OAuth applications are created by Salsify support (name + redirect URI) and are not
    tied to a user or organization. Access tokens are Bearer tokens valid for 7200
    seconds (2 hours); refresh tokens are single-use and are rotated on every refresh.
  rate_limit: 10,000 requests per hour, per organization
  docs: https://developers.salsify.com/docs/oauth2
- id: saml-sso
  name: SAML 2.0 Single Sign-On
  applies_to: Human login to the Salsify application
  description: >-
    SSO supported with AD FS 2.0, OneLogin, PingIdentity, Google Apps, Microsoft Entra ID,
    Okta, and any other SAML 2.0 identity provider.
  docs: https://developers.salsify.com/docs/sso-overview
schemes:
- name: sec0
  type: apiKey
  in: header
  parameter: Authorization
  sources:
  - openapi/salsify-api-settings-openapi.json
  - openapi/salsify-non-v1-endpoints-openapi.json
  - openapi/salsify-write-operations-openapi.json
- name: OAuth2 (documented, not declared in OpenAPI)
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://app.salsify.com/oauth/authorize
    tokenUrl: https://app.salsify.com/oauth/token
    refreshUrl: https://app.salsify.com/oauth/token
  sources:
  - https://developers.salsify.com/docs/oauth2
  - well-known/salsify-oauth-authorization-server.json
authorization_server_metadata:
  file: well-known/salsify-oauth-authorization-server.json
  spec: RFC 8414
  issuer: https://app.salsify.com
  code_challenge_methods_supported:
  - S256
gaps:
- >-
  The three published OpenAPI documents declare only the apiKey scheme (sec0). OAuth 2.0,
  which the docs and the RFC 8414 metadata both confirm is live, is not modelled in any
  securityScheme - so a spec-only reader under-reports Salsify's auth surface.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/salsify-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.