TESSA Marketing & Technology · Authentication Profile

Tessa Tech Authentication

Authentication

TESSA Marketing & Technology secures its APIs with none, oauth2, and admin-token across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

Digital MarketingSEOWeb DevelopmentAccessibilityAI Agent ReadinessProfessional ServicesAgent DirectoryA2AMCPAgent-NativeCompany
Methods: none, oauth2, admin-token Schemes: 4 OAuth flows: authorizationCode API key in:

Security Schemes

anonymous none
admin-token http
scheme: bearer
wordpress-mcp-oauth oauth2
· flows: authorizationCode
wordpress-application-passwords http
scheme: basic

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
docs: https://tessa.tech/.well-known/oauth-authorization-server
source: >-
  The provider's OpenAPI (openapi/tessa-tech-agent-directory-openapi.yml) declares NO securitySchemes and no
  security requirements, so 0-working/derive-authentication.py correctly produced nothing. This profile is
  assembled instead from live anonymous probes of every surface on 2026-09-19 and from the two OAuth discovery
  documents TESSA publishes on its apex (well-known/tessa-tech-oauth-authorization-server.json,
  well-known/tessa-tech-oauth-protected-resource.json).
summary:
  types: [none, oauth2, admin-token]
  api_key_in: []
  oauth2_flows: [authorizationCode]
  note: >-
    Three distinct postures on two hosts. (1) Everything on aiagent.tessa.tech that an agent uses — the agent card,
    the A2A JSON-RPC endpoint, the MCP server (initialize + tools/list), the OpenAPI, the service-card fleet — is
    ANONYMOUS: no credential was sent to any of them and none challenged. (2) A handful of operator routes on the
    same host (/admin/*, /internal/*) answer 401 {"detail":"Invalid or missing admin token"} — a bearer/admin token
    the OpenAPI does not describe. (3) The WordPress MCP server on tessa.tech is OAuth 2.1: RFC 8414 metadata names
    the issuer, endpoints, PKCE S256, public clients only (token_endpoint_auth_methods_supported ["none"]), a single
    scope "mcp", and client_id_metadata_document_supported true — the MCP-authorization client-registration
    pattern in which the client_id is an https URL to a metadata document instead of a pre-registered id.
schemes:
  - name: anonymous
    type: none
    surfaces:
      - https://aiagent.tessa.tech/.well-known/agent-card.json
      - https://aiagent.tessa.tech/a2a (JSON-RPC; tasks/get answered with A2A -32001 for an unknown id)
      - https://aiagent.tessa.tech/mcp/ (initialize 200, tools/list 200 with 10 tools; session via mcp-session-id header)
      - https://aiagent.tessa.tech/openapi.json, /docs, /redoc, /healthz, /s, /s/{slug}/agent-card.json
    evidence: No WWW-Authenticate on any response; no securitySchemes in the spec; no RFC 9728 document on aiagent.tessa.tech (404).
    agent_note: >-
      The four side-effecting MCP tools / A2A skills (request_strategy_session, request_introduction, claim_listing,
      request_quote) are reachable with no credential. The only identity input is the prospect_email / claim_email
      the caller supplies; TESSA verifies claims out-of-band by email within one business day per the tool text.
  - name: admin-token
    type: http
    scheme: bearer
    declared_in_spec: false
    surfaces: [/admin/requests, /admin/first-hit, /internal/visibility, /internal/visibility.json]
    evidence: 'HTTP 401 {"detail":"Invalid or missing admin token"} on GET /admin/requests and GET /internal/visibility.json (2026-09-19). Header name not disclosed.'
  - name: wordpress-mcp-oauth
    type: oauth2
    resource: https://tessa.tech/wp-json/mcp/mcp-oauth-server
    flows:
      - flow: authorizationCode
        authorizationUrl: https://tessa.tech/oauth/authorize
        tokenUrl: https://tessa.tech/oauth/token
        refreshUrl: https://tessa.tech/oauth/token
        revocationUrl: https://tessa.tech/oauth/revoke
        pkce: S256
        scopes:
          mcp: Access the WordPress MCP server (the only scope the authorization server advertises; no description is published).
    issuer: https://tessa.tech
    response_types_supported: [code]
    grant_types_supported: [authorization_code, refresh_token]
    token_endpoint_auth_methods_supported: [none]
    client_registration: OAuth Client ID Metadata Documents (client_id_metadata_document_supported true); no /register endpoint advertised (RFC 7591 dynamic registration not offered)
    authorization_response_iss_parameter_supported: true
    bearer_methods_supported: [header]
    discovery:
      authorization_server: well-known/tessa-tech-oauth-authorization-server.json
      protected_resource: well-known/tessa-tech-oauth-protected-resource.json
    evidence: >-
      Anonymous POST tools/list to the resource returned 401 {"code":"mcp_unauthorized","message":"MCP authentication
      required."} with no WWW-Authenticate header; both discovery documents fetched 200 on 2026-09-19.
    sources: [well-known/tessa-tech-oauth-authorization-server.json, well-known/tessa-tech-oauth-protected-resource.json]
  - name: wordpress-application-passwords
    type: http
    scheme: basic
    surfaces: [https://tessa.tech/wp-json/ (core WordPress REST API, wp/v2 and plugin namespaces)]
    evidence: 'The WP REST index advertises authentication.application-passwords with authorization endpoint https://tessa.tech/wp-admin/authorize-application.php. Recorded because it is published; the WordPress REST API is not one of the API entries in apis.yml.'
see_also:
  scopes: scopes/tessa-tech-scopes.yml
  mcp: mcp/tessa-tech-mcp.yml
  well_known: well-known/tessa-tech-well-known.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tessa-tech-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.