The Companies API · Authentication Profile
Thecompaniesapi Authentication
Authentication
The Companies API secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.
Company DataData EnrichmentFirmographicsWeb IntelligenceB2B DataReference DataCompany Search
Methods: apiKey
Schemes: 1
OAuth flows:
API key in: header
Security Schemes
apiKey apiKey
· in: header (Authorization)
Source
Authentication Profile
generated: '2026-08-14'
method: searched
source: https://www.thecompaniesapi.com/api/authentication (docs) + openapi/thecompaniesapi-actions-api-openapi.yml,
openapi/thecompaniesapi-analytics-api-openapi.yml, openapi/thecompaniesapi-companies-api-openapi.yml,
openapi/thecompaniesapi-industries-api-openapi.yml, openapi/thecompaniesapi-job-titles-api-openapi.yml,
openapi/thecompaniesapi-lists-api-openapi.yml, openapi/thecompaniesapi-locations-api-openapi.yml, openapi/thecompaniesapi-prompts-api-openapi.yml,
openapi/thecompaniesapi-teams-api-openapi.yml, openapi/thecompaniesapi-technologies-api-openapi.yml,
openapi/thecompaniesapi-users-api-openapi.yml, openapi/thecompaniesapi-utilities-api-openapi.yml
summary:
types:
- apiKey
api_key_in:
- header
schemes:
- name: apiKey
type: apiKey
in: header
parameter: Authorization
description: API token passed in the Authorization header, value prefixed "Basic ". Tokens are permanent
and managed on the API tokens page in account settings.
sources:
- openapi/thecompaniesapi-actions-api-openapi.yml
- openapi/thecompaniesapi-analytics-api-openapi.yml
- openapi/thecompaniesapi-companies-api-openapi.yml
- openapi/thecompaniesapi-industries-api-openapi.yml
- openapi/thecompaniesapi-job-titles-api-openapi.yml
- openapi/thecompaniesapi-lists-api-openapi.yml
- openapi/thecompaniesapi-locations-api-openapi.yml
- openapi/thecompaniesapi-prompts-api-openapi.yml
- openapi/thecompaniesapi-teams-api-openapi.yml
- openapi/thecompaniesapi-technologies-api-openapi.yml
- openapi/thecompaniesapi-users-api-openapi.yml
- openapi/thecompaniesapi-utilities-api-openapi.yml
- https://www.thecompaniesapi.com/api/authentication
value_format: Basic <api-token>
docs: https://www.thecompaniesapi.com/api/authentication
docs: https://www.thecompaniesapi.com/api/authentication
note: 'The published OpenAPI declares only `apiKey in header: Authorization` with no value format. The
authentication documentation is explicit that the header value must be prefixed "Basic " — `Authorization:
Basic MY-API-TOKEN`. A client generated from the spec alone sends a bare token and receives 401 missingApiSecret.
Despite the keyword, this is NOT RFC 7617 HTTP Basic: the value is a raw token, not a base64 user:pass
pair. Tokens are documented as permanent and never expiring, managed on the API tokens page in account
settings. New accounts receive 500 free credits with no credit card.'
token_lifetime: permanent — documented as never expiring
alternatives:
- name: token query parameter
in: query
parameter: token
example: https://api.thecompaniesapi.com/v2/companies/{domain}?token=MY-API-TOKEN
docs: https://www.thecompaniesapi.com/api/authentication
note: Documented as "mostly used to quickly test an endpoint". Not declared in the OpenAPI. Places the
credential in the URL where it lands in logs, referrers and browser history — an agent should use
the header.
oauth2: false
scopes: null
scopes_note: No OAuth2 and no scope surface; a token carries full account privileges ("Your API tokens
carry many privileges, so keep them secure!").
rotation:
documented: false
note: Tokens can be created and deleted from the settings page; no rotation policy, expiry or key-versioning
scheme is published.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/thecompaniesapi-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.