UK Civil Aviation Authority · Authentication Profile

Uk Caa Authentication

Authentication

Authentication profile for every UK Civil Aviation Authority API surface that was probed. The one documented, publicly callable API on a caa.co.uk domain — the Citizen Space consultations API — requires NO authentication at all. That is a documented posture, not an omission: the vendor developer guide the CAA links to states verbatim that "the current version of the API provides read-only access to publicly visible data. This means that no authentication is required as the access level is the same as a public visitor to the site." The remaining CAA surfaces are gated by mechanisms that are not developer authentication (browser-origin locking, reCAPTCHA, ADFS WS-Federation employee/licence-holder sign-in, or a paid order form).

UK Civil Aviation Authority secures its APIs with none across 0 declared security schemes, as derived from its OpenAPI definitions.

TravelUnited KingdomAviationAirlineAirportsRegulatorGovernmentDistributionConsumer ProtectionOpen Data
Methods: none Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-07-28'
method: searched
source: >-
  https://consultations.caa.co.uk/api/2.4/ and
  https://help.delib.net/article/350-api-v2-x-developers-guide (the vendor guide the
  CAA's own API reference links to), plus a live anonymous request verified
  2026-07-28.
docs: https://help.delib.net/article/350-api-v2-x-developers-guide
description: >-
  Authentication profile for every UK Civil Aviation Authority API surface that was
  probed. The one documented, publicly callable API on a caa.co.uk domain — the
  Citizen Space consultations API — requires NO authentication at all. That is a
  documented posture, not an omission: the vendor developer guide the CAA links to
  states verbatim that "the current version of the API provides read-only access to
  publicly visible data. This means that no authentication is required as the access
  level is the same as a public visitor to the site." The remaining CAA surfaces are
  gated by mechanisms that are not developer authentication (browser-origin locking,
  reCAPTCHA, ADFS WS-Federation employee/licence-holder sign-in, or a paid order
  form).
summary:
  types: [none]
  api_key_in: []
  oauth2_flows: []
  note: >-
    The OpenAPI carries no securitySchemes because the API genuinely declares none.
    derive-authentication.py therefore produced no profile; this file was written
    from the published documentation instead.
schemes: []
surfaces:
  - name: CAA Consultations API (Citizen Space 2.4)
    base_url: https://consultations.caa.co.uk/api/2.4
    auth: none
    verified: '2026-07-28'
    evidence: >-
      Anonymous GET /api/2.4/json_search_results?st=open&fields=all returned HTTP
      200, application/json, 57,395 bytes with no key, no header, no cookie and no
      signup. Response headers include access-control-allow-origin: * — the API is
      callable directly from a browser on any origin.
    transport_security:
      https: true
      hsts: true
      hsts_max_age: 31536000
      cors: '*'
    read_only: true
    docs: https://consultations.caa.co.uk/api/2.4/
  - name: G-INFO aircraft register search backend
    base_url: https://ginfoapi.caa.co.uk/api/aircraft
    auth: none-published
    gate: browser-origin
    evidence: >-
      Undocumented internal backend for the CAA's own G-INFO search widget. GET
      returns 405; an unauthenticated POST returns 400 with response header
      access-control-allow-origin: https://www.caa.co.uk. There is no published
      credential a developer can obtain — this is origin pinning, not authentication.
  - name: Check an ATOL search backend
    base_url: https://aircraftapi.caa.co.uk/api/checkanatol
    auth: none-published
    gate: browser-origin + reCAPTCHA
    evidence: >-
      Undocumented internal backend for the Check an ATOL widget. GET returns 405,
      unauthenticated POST returns 400, origin-locked to https://www.caa.co.uk, and
      the host page carries a data-recaptchasitekey attribute.
  - name: CAA Customer Portal
    base_url: https://portal.caa.co.uk
    auth: ws-federation
    idp: https://sso.caa.co.uk
    evidence: >-
      portal.caa.co.uk redirects to an ADFS WS-Federation sign-in at sso.caa.co.uk.
      This is a licence/certificate-holder login, not a developer credential; no
      OIDC discovery document is served (/.well-known/openid-configuration -> 404).
  - name: Bulk G-INFO aircraft register
    auth: commercial
    evidence: >-
      Paid subscription ordered on a form and emailed as an MS Excel file, licensed
      for use on a single PC. A commercial agreement, not an API credential.
gaps:
  - No API key programme, no OAuth 2.0 authorization server, no OIDC discovery, and
    no mTLS on any CAA API host.
  - No published API terms of service, rate-limit policy or SLA for the one
    documented API.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/uk-caa-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.