TESSA Marketing & Technology · Authentication Profile
Tessa Tech Authentication
Authentication
TESSA Marketing & Technology secures its APIs with none, oauth2, and admin-token across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
Digital MarketingSEOWeb DevelopmentAccessibilityAI Agent ReadinessProfessional ServicesAgent DirectoryA2AMCPAgent-NativeCompany
Methods: none, oauth2, admin-token
Schemes: 4
OAuth flows: authorizationCode
API key in:
Security Schemes
anonymous none
admin-token http
scheme: bearer
wordpress-mcp-oauth oauth2
· flows: authorizationCode
wordpress-application-passwords http
scheme: basic
Source
Authentication Profile
generated: '2026-09-19'
method: searched
docs: https://tessa.tech/.well-known/oauth-authorization-server
source: >-
The provider's OpenAPI (openapi/tessa-tech-agent-directory-openapi.yml) declares NO securitySchemes and no
security requirements, so 0-working/derive-authentication.py correctly produced nothing. This profile is
assembled instead from live anonymous probes of every surface on 2026-09-19 and from the two OAuth discovery
documents TESSA publishes on its apex (well-known/tessa-tech-oauth-authorization-server.json,
well-known/tessa-tech-oauth-protected-resource.json).
summary:
types: [none, oauth2, admin-token]
api_key_in: []
oauth2_flows: [authorizationCode]
note: >-
Three distinct postures on two hosts. (1) Everything on aiagent.tessa.tech that an agent uses — the agent card,
the A2A JSON-RPC endpoint, the MCP server (initialize + tools/list), the OpenAPI, the service-card fleet — is
ANONYMOUS: no credential was sent to any of them and none challenged. (2) A handful of operator routes on the
same host (/admin/*, /internal/*) answer 401 {"detail":"Invalid or missing admin token"} — a bearer/admin token
the OpenAPI does not describe. (3) The WordPress MCP server on tessa.tech is OAuth 2.1: RFC 8414 metadata names
the issuer, endpoints, PKCE S256, public clients only (token_endpoint_auth_methods_supported ["none"]), a single
scope "mcp", and client_id_metadata_document_supported true — the MCP-authorization client-registration
pattern in which the client_id is an https URL to a metadata document instead of a pre-registered id.
schemes:
- name: anonymous
type: none
surfaces:
- https://aiagent.tessa.tech/.well-known/agent-card.json
- https://aiagent.tessa.tech/a2a (JSON-RPC; tasks/get answered with A2A -32001 for an unknown id)
- https://aiagent.tessa.tech/mcp/ (initialize 200, tools/list 200 with 10 tools; session via mcp-session-id header)
- https://aiagent.tessa.tech/openapi.json, /docs, /redoc, /healthz, /s, /s/{slug}/agent-card.json
evidence: No WWW-Authenticate on any response; no securitySchemes in the spec; no RFC 9728 document on aiagent.tessa.tech (404).
agent_note: >-
The four side-effecting MCP tools / A2A skills (request_strategy_session, request_introduction, claim_listing,
request_quote) are reachable with no credential. The only identity input is the prospect_email / claim_email
the caller supplies; TESSA verifies claims out-of-band by email within one business day per the tool text.
- name: admin-token
type: http
scheme: bearer
declared_in_spec: false
surfaces: [/admin/requests, /admin/first-hit, /internal/visibility, /internal/visibility.json]
evidence: 'HTTP 401 {"detail":"Invalid or missing admin token"} on GET /admin/requests and GET /internal/visibility.json (2026-09-19). Header name not disclosed.'
- name: wordpress-mcp-oauth
type: oauth2
resource: https://tessa.tech/wp-json/mcp/mcp-oauth-server
flows:
- flow: authorizationCode
authorizationUrl: https://tessa.tech/oauth/authorize
tokenUrl: https://tessa.tech/oauth/token
refreshUrl: https://tessa.tech/oauth/token
revocationUrl: https://tessa.tech/oauth/revoke
pkce: S256
scopes:
mcp: Access the WordPress MCP server (the only scope the authorization server advertises; no description is published).
issuer: https://tessa.tech
response_types_supported: [code]
grant_types_supported: [authorization_code, refresh_token]
token_endpoint_auth_methods_supported: [none]
client_registration: OAuth Client ID Metadata Documents (client_id_metadata_document_supported true); no /register endpoint advertised (RFC 7591 dynamic registration not offered)
authorization_response_iss_parameter_supported: true
bearer_methods_supported: [header]
discovery:
authorization_server: well-known/tessa-tech-oauth-authorization-server.json
protected_resource: well-known/tessa-tech-oauth-protected-resource.json
evidence: >-
Anonymous POST tools/list to the resource returned 401 {"code":"mcp_unauthorized","message":"MCP authentication
required."} with no WWW-Authenticate header; both discovery documents fetched 200 on 2026-09-19.
sources: [well-known/tessa-tech-oauth-authorization-server.json, well-known/tessa-tech-oauth-protected-resource.json]
- name: wordpress-application-passwords
type: http
scheme: basic
surfaces: [https://tessa.tech/wp-json/ (core WordPress REST API, wp/v2 and plugin namespaces)]
evidence: 'The WP REST index advertises authentication.application-passwords with authorization endpoint https://tessa.tech/wp-admin/authorize-application.php. Recorded because it is published; the WordPress REST API is not one of the API entries in apis.yml.'
see_also:
scopes: scopes/tessa-tech-scopes.yml
mcp: mcp/tessa-tech-mcp.yml
well_known: well-known/tessa-tech-well-known.yml
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tessa-tech-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.