Ualá · Authentication Profile

Ual Authentication

Authentication

Ualá secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the client_credentials (custom JSON body, non-RFC 6749 encoding) flow(s).

CompanyFintechPaymentsBankingNeobankCheckoutE-CommerceArgentinaMexico
Methods: http Schemes: 1 OAuth flows: client_credentials (custom JSON body, non-RFC 6749 encoding) API key in:

Security Schemes

bearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-07-21'
method: searched
source: https://developers.ualabis.com.ar/v2/authentication/create
docs: https://developers.ualabis.com.ar/v2/authentication/create
summary:
  types:
  - http
  oauth2_flows:
  - client_credentials (custom JSON body, non-RFC 6749 encoding)
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  description: >-
    All Ualá Bis Cobros Online v2 endpoints require Authorization: Bearer <token>. The token
    is created via POST /auth/token on https://auth.developers.ar.ua.la/v2/api (test:
    https://auth.stage.developers.ar.ua.la/v2/api) with a JSON body of username, client_id,
    client_secret_id and grant_type=client_credentials — an OAuth2-style client-credentials
    exchange carried in custom JSON rather than RFC 6749 form encoding. Credentials for both
    test and production are issued in the Ualá Bis welcome email and shown in the mobile/web
    apps; they are private and Ualá staff never request them.
  token_endpoint:
    production: https://auth.developers.ar.ua.la/v2/api/auth/token
    test: https://auth.stage.developers.ar.ua.la/v2/api/auth/token
  sources:
  - openapi/ual-bis-cobros-online-v2-openapi.yml
  - openapi/ual-bis-auth-v2-openapi.yml
notes: >-
  No API-key or OpenID Connect surface; no OAuth scopes are documented (scopes/ intentionally
  omitted).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ual-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.