Saperly · Authentication Profile

Saperly Authentication

Authentication

Saperly declares 2 security scheme(s) across its OpenAPI definitions.

TelephonyVoiceSMSPhone NumbersAI AgentsConsentComplianceMCPMessagingCommunications
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

bearerApiKey http
scheme: bearer
mcpOAuth oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-10-07'
method: searched
source: https://saperly.com/docs/guides/authentication; https://saperly.com/docs/api-reference; https://saperly.com/docs/sdks/mcp;
  https://api.saperly.com/.well-known/oauth-protected-resource and https://saperly.com/.well-known/oauth-authorization-server
  (probed 2026-10-07). The OpenAPI contract declares no securitySchemes.
docs: https://saperly.com/docs/guides/authentication
schemes:
- name: bearerApiKey
  type: http
  scheme: bearer
  header: Authorization
  key_prefix: sap_sk_live_
  description: 'One tier of scoped API key. Every request sends Authorization: Bearer sap_sk_live_…; the key carries
    scopes (read | write | admin), an optional number allow-list and an optional spend cap, and the workspace is
    always resolved from the key, never from client input. Keys are created in the dashboard (Settings → Keys) or
    minted as ceiling-bounded child keys by an admin-scoped key via POST /api-tokens; the plaintext token is returned
    once.'
  scopes:
  - read
  - write
  - admin
  applies_to: REST API and the MCP endpoint
- name: mcpOAuth
  type: oauth2
  flow: authorizationCode
  description: 'MCP OAuth 2.1 for https://api.saperly.com/mcp: RFC 9728 protected-resource metadata names https://saperly.com
    as the authorization server; authorization code with PKCE S256, refresh tokens, dynamic client registration.'
  authorization_url: https://saperly.com/api/auth/mcp/authorize
  token_url: https://saperly.com/api/auth/mcp/token
  registration_url: https://saperly.com/api/auth/mcp/register
  jwks_uri: https://saperly.com/api/auth/mcp/jwks
  pkce:
  - S256
  scopes:
  - openid
  - profile
  - email
  - offline_access
  resource: https://api.saperly.com/mcp
  applies_to: MCP endpoint only
errors:
  '401': Unauthorized — no bearer token on the request
  '403': AuthorizationDenied — unrecognized, revoked, missing scope, or number outside the allow-list
  '402': SpendLimitExceeded — the key's spend cap was hit at reserve time
notes: Human dashboard members get abilities from their org role (owner/admin vs member) rather than a key grant.
  No OAuth is offered for the REST API itself.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/saperly-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.