Saperly · Authentication Profile
Saperly Authentication
Authentication
Saperly declares 2 security scheme(s) across its OpenAPI definitions.
TelephonyVoiceSMSPhone NumbersAI AgentsConsentComplianceMCPMessagingCommunications
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
bearerApiKey http
scheme: bearer
mcpOAuth oauth2
Source
Authentication Profile
generated: '2026-10-07'
method: searched
source: https://saperly.com/docs/guides/authentication; https://saperly.com/docs/api-reference; https://saperly.com/docs/sdks/mcp;
https://api.saperly.com/.well-known/oauth-protected-resource and https://saperly.com/.well-known/oauth-authorization-server
(probed 2026-10-07). The OpenAPI contract declares no securitySchemes.
docs: https://saperly.com/docs/guides/authentication
schemes:
- name: bearerApiKey
type: http
scheme: bearer
header: Authorization
key_prefix: sap_sk_live_
description: 'One tier of scoped API key. Every request sends Authorization: Bearer sap_sk_live_…; the key carries
scopes (read | write | admin), an optional number allow-list and an optional spend cap, and the workspace is
always resolved from the key, never from client input. Keys are created in the dashboard (Settings → Keys) or
minted as ceiling-bounded child keys by an admin-scoped key via POST /api-tokens; the plaintext token is returned
once.'
scopes:
- read
- write
- admin
applies_to: REST API and the MCP endpoint
- name: mcpOAuth
type: oauth2
flow: authorizationCode
description: 'MCP OAuth 2.1 for https://api.saperly.com/mcp: RFC 9728 protected-resource metadata names https://saperly.com
as the authorization server; authorization code with PKCE S256, refresh tokens, dynamic client registration.'
authorization_url: https://saperly.com/api/auth/mcp/authorize
token_url: https://saperly.com/api/auth/mcp/token
registration_url: https://saperly.com/api/auth/mcp/register
jwks_uri: https://saperly.com/api/auth/mcp/jwks
pkce:
- S256
scopes:
- openid
- profile
- email
- offline_access
resource: https://api.saperly.com/mcp
applies_to: MCP endpoint only
errors:
'401': Unauthorized — no bearer token on the request
'403': AuthorizationDenied — unrecognized, revoked, missing scope, or number outside the allow-list
'402': SpendLimitExceeded — the key's spend cap was hit at reserve time
notes: Human dashboard members get abilities from their org role (owner/admin vs member) rather than a key grant.
No OAuth is offered for the REST API itself.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/saperly-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.