SPS Commerce · Authentication Profile

Sps Commerce Authentication

Authentication

SPS Commerce secures its APIs with http and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions.

CompanyEDIRetailSupply ChainCommerceTrading PartnersAPI Standards
Methods: http, oauth2 Schemes: 3 OAuth flows: API key in:

Security Schemes

SpsBearer http
scheme: bearer
HTTPBearer http
scheme: bearer
Dev Center OAuth 2.0 oauth2
· flows: ,

Source

Authentication Profile

Raw ↑
generated: '2026-10-09'
method: searched
source: https://developercenter.spscommerce.com/#/docs/new-authentication-docs/getting-an-access-token
docs: https://developercenter.spscommerce.com/#/docs/authentication
docs_pages:
- https://developercenter.spscommerce.com/#/docs/authentication
- https://developercenter.spscommerce.com/#/docs/new-authentication-docs/getting-an-access-token
- https://developercenter.spscommerce.com/#/docs/new-authentication-docs/machine2machine-applications
- https://developercenter.spscommerce.com/#/docs/new-authentication-docs/using-an-access-token
- https://developercenter.spscommerce.com/#/docs/new-authentication-docs/refresh-tokens
- https://developercenter.spscommerce.com/#/docs/new-authentication-docs/authentication-keys
- https://developercenter.spscommerce.com/#/docs/new-authentication-docs/troubleshooting-common-issues
- https://developercenter.spscommerce.com/#/docs/new-authentication-docs/client-updates-for-enhanced-security
summary:
  types:
  - http
  - oauth2
  note: The OpenAPI contracts declare only HTTP bearer; the Dev Center docs state "Dev Center follows standard OAuth protocols for authenticating and authorizing API requests." Bearer tokens are OAuth 2.0 access tokens issued per Dev Center application.
schemes:
- name: SpsBearer
  type: http
  scheme: bearer
  description: |-
    Bearer authentication specify's a bearer token in the 'Authorization' header following the format:
    Authorization: Bearer <token>
  sources:
  - openapi/sps-commerce-inventory-api-openapi.yml
  - openapi/sps-commerce-submission-api-openapi.yml
- name: HTTPBearer
  type: http
  scheme: bearer
  sources:
  - openapi/sps-commerce-submission-api-openapi.yml
- name: Dev Center OAuth 2.0
  type: oauth2
  description: "The SPS Dev Center follows the OAuth 2.0 industry standard to allow secure authorization in a simple and standard way."
  application_types:
  - Web Service Applications (partners should use this type)
  - Native Applications (authorization code with code verifier / code challenge, PKCE)
  - Single Page Applications (implicit flow deprecated; must migrate to Authorization Code Flow with PKCE using the Auth0 SPA SDK by July 1st, 2026)
  - Machine-to-Machine Applications (Client Credentials Grant)
  flows:
    clientCredentials:
      token_endpoint: POST /oauth/token
      parameters: [audience, client_id, client_secret, grant_type]
      audience: https://spscommerce.com
      legacy_audience: api://api.spscommerce.com/
    authorizationCode:
      authorize_endpoint: GET /authorize
      redirect_uri: must exactly match a redirect URL registered for the Dev Center app (mismatch returns 403)
      pkce: required for Native and Single Page Applications
  refresh_tokens: "Refresh Tokens enable you to get a new Access Token when the current one has expired. Since they don't expire, handle and store them with great care so they are not compromised."
  token_check: GET /auth-check returns 204 No Content for a valid bearer token
  credentials: App ID and App Secret per Dev Center application; separate Sandbox Keys and Production Keys
  source: https://developercenter.spscommerce.com/#/docs/new-authentication-docs/machine2machine-applications

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/sps-commerce-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.