Swiss Food Composition Database · Authentication Profile

Swiss Food Composition Database Authentication

Authentication

Swiss Food Composition Database declares 0 security scheme(s) across its OpenAPI definitions.

FoodNutritionfood-compositionHealthOpen DataGovernmentSwitzerlandReference DataPublic SectorResearch
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  The FSVO's own API description document, "The Swiss Food Composition Database API" (published at
  https://naehrwertdaten.ch/en/downloads/), which states: "API is free to use and allows unrestricted access"
  and "All of the available endpoints and methods are nonrestricted, free to access". Corroborated by the
  served OpenAPI 3.0.1 document, which declares no components.securitySchemes and no top-level security
  requirement, and by live anonymous calls on 2026-08-27 that returned 200 with data.
docs: https://naehrwertdaten.ch/en/downloads/
summary: >-
  No authentication of any kind. There is no API key, no OAuth, no signup and no account. Every one of the 21
  operations is a public read that succeeds anonymously.
schemes: []
auth_required: false
signup_required: false
credential_types: []
transport:
  https: true
  tls_version: TLSv1.3
  http_to_https_redirect: true
cors:
  enabled: true
  access_control_allow_origin: '*'
  access_control_allow_credentials: true
  access_control_allow_methods: GET, PUT, POST, OPTIONS
  note: >-
    Observed on live responses 2026-08-27. The API is directly callable from a browser, which is how the
    provider's own Swagger UI and search application consume it.
evidence:
  - url: https://api.webapp.prod.blv.foodcase-services.com/BLV_WebApp_WS/webresources/BLV-api/versiondb
    status: 200
    note: Anonymous GET returned {"idversion":51,"versiontext":"V 7.1"} with no credential supplied.
  - url: https://api.webapp.prod.blv.foodcase-services.com/BLV_WebApp_WS/webresources/openapi.json
    status: 200
    note: Served OpenAPI declares no securitySchemes.
observations:
  - >-
    An administrative operation, GET /webresources/BLV-api/reloadCache ("Reloads the local database cache of
    the application"), is exposed on the same unauthenticated public surface as the read operations. It is
    tagged "system configuration" in the provider's own spec. This is recorded as an observation about the
    published contract; API Evangelist did not invoke it.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/swiss-food-composition-database-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.