Spot Runner · Authentication Profile
Spot Runner Authentication
Authentication
Spot Runner declares 0 security scheme(s) across its OpenAPI definitions.
CompanyAdvertisingAdTechConnected TVCTVOnline VideoContextual AdvertisingAgentic AIMedia Planning
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-08-13'
method: derived
source: >-
mcp/spot-runner-mcp-tools.json (live tools/list, HTTP 200) + llms/spot-runner-llms.txt
(https://www.spotrunner.com/llms.txt, HTTP 200)
scope: >-
This profile covers the ONLY public API surface Spot Runner exposes — the Wix Site MCP
endpoint. Spot Runner publishes no REST/GraphQL developer API, so there are no OpenAPI
securitySchemes to derive from.
surfaces:
- name: Wix Site MCP endpoint
url: https://www.spotrunner.com/_api/mcp
transport: streamable-http (JSON-RPC 2.0)
connect_auth: none
connect_evidence: >-
An anonymous POST of {"jsonrpc":"2.0","id":1,"method":"tools/list"} returned HTTP 200 with
the full 9-tool manifest. No Authorization header, API key or OAuth challenge was required
to connect or to enumerate tools. A bare GET on the same URL returns 401.
schemes:
- id: anonymous-connect
type: none
applies_to:
- tools/list
- GetBusinessDetails
- SearchInSite
- SearchSiteApiDocs
- BrowseWixRESTDocsMenu
- ReadFullDocsArticle
- ReadFullDocsMethodSchema
description: >-
Discovery and read tools require no credential. They return only information already
public on the site.
- id: visitor-token
type: bearer-like
obtained_via: GenerateVisitorToken
passed_as: visitorToken argument on the tool call (not an HTTP header)
applies_to:
- CallWixSiteAPI
- ExecuteWixAPI
required: true
description: >-
Acting tools require a short-lived Wix visitor access token. The agent calls
GenerateVisitorToken to create a visitor session, then passes the returned token as the
visitorToken argument. The token carries visitor-level authority only — it can query
site data, start a booking or begin a purchase on an anonymous visitor's behalf, but it
does not authenticate a Spot Runner customer.
evidence: >-
inputSchema for CallWixSiteAPI requires [visitorToken, url, method]; ExecuteWixAPI
requires [code, reason, hasMutations, sourceDocUrls, visitorToken].
oauth:
supported: false
evidence: >-
/.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource both
404/400 on every Spot Runner host (see well-known/spot-runner-well-known.yml).
openid_connect:
supported: false
evidence: /.well-known/openid-configuration returns no document on any host
- name: Advertiser portal backend
url: https://api.spotrunner.com
public: false
documented: false
observed_flow: passwordless-email (magic link)
evidence: >-
The portal SPA bundle (https://advertiser.spotrunner.com/assets/index-B9BDGY7_.js, HTTP
200) names /v1/auth/email/login and /v1/auth/token against the api.spotrunner.com base.
This is the portal's own private backend; Spot Runner publishes no reference or spec for
it, so no scheme is claimed beyond the observed login shape.
notes: >-
No scopes/ artifact is emitted: there is no OAuth surface and no permission model to
enumerate. Nothing here was invented — every scheme is read off a live response or the
provider's own llms.txt.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/spot-runner-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.