SniffCat · Authentication Profile
Sniffcat Authentication
Authentication
SniffCat declares 1 security scheme(s) across its OpenAPI definitions.
Threat IntelligenceIP Reputationabuse-databaseCybersecurityOSINTNetwork Securitysysadmin-toolsBlocklistabuse-reportingip-blocklistIP IntelligenceThreat Feeds
Methods:
Schemes: 1
OAuth flows:
API key in:
Security Schemes
X-Secret-Token apiKey
· in: header ()
Source
Authentication Profile
generated: '2026-08-19'
method: searched
source: https://sniffcat.com/documentation/api
docs: https://sniffcat.com/documentation/api
probe:
url: https://api.sniffcat.com/api/v1/check?ip=1.1.1.1
date: '2026-08-19'
status: 403
body: '{"success":false,"status":403,"message":"Missing API token in request headers."}'
note: >-
Derived from a live unauthenticated call, not from a spec — SniffCat publishes no OpenAPI, so
there are no securitySchemes to parse. The 403 body confirms the header is mandatory on every
endpoint.
summary: >-
A single authentication mechanism across the whole API: a static, account-scoped bearer-style
secret sent in a custom `X-Secret-Token` request header. No OAuth 2.0, no OpenID Connect, no
mutual TLS, no HTTP Basic, no signed requests, and no scope system — entitlement is expressed
through account ROLES that set daily quotas rather than through token scopes.
schemes:
- id: secretToken
type: apiKey
in: header
name: X-Secret-Token
applies_to: all endpoints (/api/v1/blacklist, /check, /reports, /report, /bulk)
required: true
description: >-
Static per-account API token. "All endpoints require the X-Secret-Token header. You can generate
a token at /api." — https://sniffcat.com/documentation/api
issuance:
url: https://sniffcat.com/api
requires_login: true
note: >-
The token page is behind the session login; probing https://sniffcat.com/api anonymously
returns the SniffCat login screen (HTTP 200, login form). Registration is self-serve at
https://sniffcat.com/register.
prefix: null
rotation: not documented
expiry: not documented
oauth2: false
openid_connect: false
mutual_tls: false
http_basic: false
request_signing: false
scopes:
supported: false
note: >-
No scope or permission strings exist. Authorization granularity is per-ROLE daily quota per
operation — see rate-limits/sniffcat-rate-limits.yml and https://sniffcat.com/documentation/roles.
authorization_model:
type: role-based-quota
roles:
- {name: Individual, trust_level: 1}
- {name: Early User, trust_level: 1.19}
- {name: Webmaster, trust_level: 1.24}
- {name: Contributor, trust_level: 1.36}
- {name: SniffCat Enthusiast, trust_level: 1.48}
- {name: Hosting Provider, trust_level: 1.54}
- {name: ISP, trust_level: 1.62}
- {name: Security Researcher, trust_level: 1.75}
- {name: Law Enforcement, trust_level: 1.83}
note: >-
Roles are additive — a user may hold several. Trust level also weights the impact of that user's
submitted reports on an IP's abuse confidence score, so the role is an authorization control AND
a data-quality control.
failure_modes:
- status: 403
condition: X-Secret-Token header absent
body: '{"success":false,"status":403,"message":"Missing API token in request headers."}'
method: probed
- status: 403
condition: token valid but the account's role grants no quota for that operation
documented_as: No quota assigned to the role / No limits configured for this role
source: https://sniffcat.com/documentation/api/blacklist, https://sniffcat.com/documentation/api/check
- status: 429
condition: daily role quota or the 400-req/120s edge window exhausted
transport:
https_only: true
hsts: 'max-age=31536000; includeSubDomains; preload'
tls_version: TLSv1.3
gaps:
- No documented token rotation, revocation or expiry policy.
- No token prefix convention, so a leaked SniffCat token is not self-identifying to a secret scanner.
- No scopes, so a token minted for read-only blacklist consumption can also submit abuse reports.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/sniffcat-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.