temp.md · Authentication Profile

Temp Md Authentication

Authentication

temp.md secures its APIs with http across 7 declared security schemes, as derived from its OpenAPI definitions.

Web PublishingStatic HostingAI AgentsMCPA2ADeveloper ToolsPreview InfrastructureFile SharingAgent-NativeCompany
Methods: http Schemes: 7 OAuth flows: API key in:

Security Schemes

tempCapability http
scheme: bearer
publishSessionToken http
scheme: bearer
accountBearer http
scheme: bearer
dashboardBearer http
scheme: bearer
applicationBearer http
scheme: bearer
publishGrantBearer http
scheme: bearer
reviewBearer http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/temp-md-openapi.yml, openapi/temp-md-platform-openapi.yml, https://temp.md/docs, https://temp.md/.well-known/agent.json, live probes 2026-09-19
docs: https://temp.md/docs#publish
summary:
  types: [http]
  schemes_count: 7
  anonymous_publish: true
  oauth2: false
  note: >-
    Everything is HTTP Bearer, and the interesting part is WHICH token: temp.md is capability-based. An anonymous
    POST /temps returns a scoped updateToken (and claimToken) that is the only credential needed to update,
    inspect, snapshot, restore or revoke that one Temp. Accounts are optional; an account session JWT or a named
    API key (prefix tempmd_key_) owns Temps, recovers lost update tokens and manages keys. The partner platform
    adds server-only Application keys (tempmd_app_<id>_<secret>, one-time reveal, explicit scopes), short-lived
    delegated publish grants (tempmd_grant_...) for browsers, and review-viewer capabilities (tempmd_view_...).
    The derive-authentication.py baseline collapsed these to one scheme because all share type http/bearer;
    this file lists each with its bearerFormat and where it is accepted.
anonymous_operations:
  note: No credential at all (security absent or an empty {} alternative in the spec)
  operations: [createTemp, createPublishSession (anonymous alternative), listTempComments, appendTempComments, signup, login, reportAbuse, getHealth, getA2AAgentCard, sendA2AJsonRpc (publish), MCP tools/list + publish_temp]
schemes:
- name: tempCapability
  type: http
  scheme: bearer
  bearerFormat: tempmd scoped capability
  what_it_is: The per-Temp updateToken returned by createTemp / finalizePublishSession (or the claimToken for status/restore). Prefix observed in docs examples "tempmd_...".
  obtained_from: response of POST /temps (updateToken, claimToken) or POST /publish-sessions/{id}/finalize
  accepted_on: [updateTemp, revokeTemp, createPublishSession (tempId update), getTempStatus, restoreTemp, snapshotTemp, updateTempCapabilitySettings]
  rotation: Claiming a Temp into an account ROTATES the update token; the old one stops working (docs#privacy, skill.md). rotateUpdateToken invalidates every prior token and returns one replacement exactly once.
  sources: [openapi/temp-md-openapi.yml]
- name: publishSessionToken
  type: http
  scheme: bearer
  bearerFormat: tempmd_upload session capability
  what_it_is: One-hour upload capability (PublishSession.uploadToken) minted by createPublishSession.
  accepted_on: [getPublishSession, uploadPublishSessionFile, finalizePublishSession]
  sources: [openapi/temp-md-openapi.yml]
- name: accountBearer
  type: http
  scheme: bearer
  bearerFormat: JWT or tempmd_key API key
  what_it_is: Account session token from POST /auth/login (LoginResult.token) or a named API key created with POST /me/api-keys (prefix tempmd_key_, secret shown once, stored hashed, max 20 active keys).
  accepted_on: [revokeTemp, createPublishSession, getTempStatus, restoreTemp, snapshotTemp, updateTempCapabilitySettings, listApiKeys, createApiKey, revokeApiKey, rotateUpdateToken, MCP connection header (list_temps, recover_update_token, account-owned publish), A2A GetTask/ListTasks]
  key_management: GET/POST /me/api-keys, DELETE /me/api-keys/{keyId}; CLI `tempmd login`, `tempmd keys`, `tempmd keys revoke <id>`
  sources: [openapi/temp-md-openapi.yml, https://temp.md/.well-known/agent.json]
- name: dashboardBearer
  type: http
  scheme: bearer
  description: A Temp.md dashboard session or personal account API key.
  accepted_on: [createOrganization, getOrganization, createApplication, getApplication, updateApplication, listApplicationKeys, createApplicationKey, revokeApplicationKey, webhook endpoint + domain binding operations]
  sources: [openapi/temp-md-platform-openapi.yml]
- name: applicationBearer
  type: http
  scheme: bearer
  bearerFormat: tempmd_app_<id>_<secret>
  description: Server-only Application key with explicit scopes. Returned once; must never reach a browser or Electron renderer.
  accepted_on: [listPlatformPreviews, getPlatformPreview, revokePlatformPreview, createPublishGrant, revokePublishGrant, createPlatformPublishSession, listReviewRequests, createReviewRequest, getPlatformUsage]
  sources: [openapi/temp-md-platform-openapi.yml, https://temp.md/llms.txt]
- name: publishGrantBearer
  type: http
  scheme: bearer
  bearerFormat: tempmd_grant_<id>_<secret>
  description: Short-lived, one-session delegated publishing authority (backend mints a 5-15 minute grant; requests carrying an Origin header MUST use a grant, not an Application key).
  accepted_on: [createPlatformPublishSession]
  sources: [openapi/temp-md-platform-openapi.yml, https://temp.md/llms.txt]
- name: reviewBearer
  type: http
  scheme: bearer
  bearerFormat: tempmd_view_<id>_<secret>
  description: Short-lived viewer capability bound to one frozen review request.
  accepted_on: [getReviewRequest, createReviewDecision]
  sources: [openapi/temp-md-platform-openapi.yml]
headers:
  authorization: 'Authorization: Bearer <token>'
  client_identity: 'X-Tempmd-Client: product/version (optional, sanitized attribution only; pattern ^[A-Za-z0-9][A-Za-z0-9._+/@-]{0,79}$; never user data or capabilities)'
cors:
  note: Capability-backed publish-session, status, update and revoke routes allow credential-free cross-origin requests; account, claim, settings, restore, snapshot and dashboard routes keep a restricted-origin policy. Do not send cookies. (docs#browser-integrations)
signup:
  self_serve: true
  operations: [signup, login]
  dashboard: https://temp.md/dashboard
  note: Not required to publish.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/temp-md-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.