Soothe · Authentication Profile

Soothe Authentication

Authentication

Soothe declares 0 security scheme(s) across its OpenAPI definitions.

CompanyWellnessHealth and WellnessMassageMarketplaceOn-Demand ServicesBeautyCorporate WellnessHospitalityConsumer ServicesLocal ServicesBooking
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-08-28'
method: probed
source: >-
  openapi/soothe-help-center-mirror-openapi.json (no securitySchemes) plus live probes of
  https://api.soothe.com/ and https://www.soothe.com/sign_on/
summary:
  types: []
  api_key_in: []
  oauth2_flows: []
schemes: []
note: >-
  Soothe publishes no authenticated API contract. The only machine-readable spec it
  serves — the help-centre mirror schema — declares no components.securitySchemes and no
  security requirement on any operation; that surface is anonymous read-only content.
  The company's actual API host, api.soothe.com, is not anonymous: every request 301s to
  /users/sign_in and returns a Rails/Devise session login form (page title "Api | Log
  In") carrying a CSRF token. That is a browser session login, not a documented API
  credential scheme, and no key type, header, scope model or token endpoint is published
  anywhere on soothe.com. Recorded as an honest absence rather than guessed.
observed:
- host: https://api.soothe.com
  status: 301
  redirect: https://api.soothe.com/users/sign_in
  mechanism: rails-devise-session-login
  evidence: 'HTML form with authenticity_token; <title>Api | Log In </title>'
  documented: false
- host: https://www.soothe.com/sign_on/
  status: 200
  mechanism: consumer-account-login
  documented: false
- host: https://help.soothe.com
  status: 200
  mechanism: none
  note: anonymous, unauthenticated read-only content service

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/soothe-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.