Trello Authentication
Trello runs two authorization systems side by side. The legacy Trello Auth system passes an API key and a user token, by default as QUERY PARAMETERS - which is what both apiKey schemes in the OpenAPI declare, and which puts credentials in logs, proxies and browser history. Trello also documents an Authorization header form (OAuth oauth_consumer_key="{key}", oauth_token="{token}") and a request-body form, and an agent should prefer the header. OAuth 2.0 3LO reached GA on 2026-09-15 with ten granular scopes, short-lived refreshable tokens and resource restrictions; see scopes/trello-scopes.yml. OAuth 1.0a is also still supported. Tokens are user-revocable at https://trello.com/u/{username}/account and via DELETE /1/tokens/{token}; a revoked token returns HTTP 401 with the plain-text body "invalid token".
Trello secures its APIs with apiKey and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.