SMKlog · Authentication Profile

Smklog Com Authentication

Authentication

SMKlog secures its APIs with none and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).

CompanyShippingLogisticsParcel Shippingshipping-ratesShipping LabelsE-CommerceAgentsMCPA2A
Methods: none, oauth2 Schemes: 2 OAuth flows: clientCredentials API key in:

Security Schemes

anonymous none
SMKlog client_credentials oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
docs: https://smklog.com/auth.md
source: >-
  https://smklog.com/auth.md (saved verbatim as authentication/smklog-com-auth.md), the RFC 8414 / RFC 9728
  metadata on both hosts (well-known/), the MCP server card authentication block, and the OpenAPI, which declares
  no securitySchemes at all — 0-working/derive-authentication.py therefore produced no profile and this file is
  hand-written from the provider's own documents.
summary:
  types: [none, oauth2]
  required: false
  api_key_in: []
  oauth2_flows: [clientCredentials]
  default: anonymous — every operation answers without credentials
schemes:
- name: anonymous
  type: none
  applies_to: [getParcelQuote, createPaymentSession, getCheckoutStatus, status, 'MCP tools/list + tools/call', 'A2A message/send']
  note: >-
    "The API works without credentials: rate quotes and payment sessions are open, rate limited per client per
    hour." (auth.md). The protected-resource document on the API host states authorization_required false.
- name: SMKlog client_credentials
  type: oauth2
  flow: clientCredentials
  issuer: https://quote-api.smklog.com
  tokenUrl: https://quote-api.smklog.com/oauth/token
  token_endpoint_auth_methods: [client_secret_basic, client_secret_post]
  scopes: [quote]
  bearer: 'Authorization: Bearer smk_at_... on POST /quote'
  token_lifetime: one hour
  purpose: >-
    "Credentials exist for one reason — an agent whose legitimate traffic outgrows the anonymous limits gets its
    own hourly bucket at its own size." Not identity, not authorization for payment.
  registration: manual — email info@smklog.com with what you are building and the expected volume; the secret is shown once
  failure: '401 invalid_token on an expired or revoked token; "the request is never silently downgraded to anonymous limits, so failures are loud"'
  sources: [https://smklog.com/auth.md, https://quote-api.smklog.com/.well-known/oauth-authorization-server]
capabilities:
  session_id: >-
    createPaymentSession returns an opaque session_id (pattern ^as_[A-Za-z0-9-]{8,80}$) that is the only thing
    needed to read that session's status — a bearer-by-knowledge capability, unauthenticated otherwise; the
    status answer "never carries names, addresses or emails".
observed:
- 'POST /oauth/token without credentials -> 401 application/json {"error":"invalid_client"} (2026-09-19)'
- 'POST /quote with an empty body, no credentials -> 400 missing_required_fields (the anonymous path works; nothing challenged for auth)'
detail: scopes/smklog-com-scopes.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/smklog-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.