U.S. Department of Transportation · Authentication Profile

Us Dot Authentication

Authentication

U.S. Department of Transportation secures its APIs with none and apiKey across 8 declared security schemes, as derived from its OpenAPI definitions.

TravelUnited StatesAviationAirlinesAirportsGovernmentRegulatorDistributionAviation Consumer ProtectionOpen DataTransportationSafetyStatisticsAutomotiveRail
Methods: none, apiKey Schemes: 8 OAuth flows: API key in: header, query

Security Schemes

apiKey apiKey
· in: header (X-API-KEY)
appId apiKey
· in: header (X-APP-ID)
clientIdHeader apiKey
· in: header (client_id)
clientSecretHeader apiKey
· in: header (client_secret)
socrataAppToken apiKey
· in: header (X-App-Token)
fmcsaWebKey apiKey
· in: query (webKey)
fraWebServiceAccount http
scheme: unspecified
odeOperatorDefined none

Source

Authentication Profile

Raw ↑
generated: '2026-07-28'
method: searched
source: >-
  openapi/us-dot-faa-safety-assurance-system-api-openapi.yml (securitySchemes),
  openapi/us-dot-faa-air-carrier-prd-api-openapi.yml (header parameters),
  https://api.faa.gov/s/, https://mobile.fmcsa.dot.gov/QCDevsite/,
  https://safetydata.fra.dot.gov/MasterWebService/FRASafetyDataAPIs.aspx,
  https://dev.socrata.com/docs/app-tokens.html, live probes 2026-07-28
summary:
  types:
  - none
  - apiKey
  api_key_in:
  - header
  - query
  oauth2_flows: []
  openid_connect: false
  mutual_tls: false
  detail: >-
    U.S. DOT uses NO OAuth 2.0 and NO OpenID Connect on any API. Every credentialed
    surface is a static key or key-pair sent in request headers. The majority of the
    department's API surface area requires no credential at all. There is no departmental
    identity layer for API consumers — Login.gov appears once, in front of FMCSA key
    issuance, not in front of an API.
  spec_gap: >-
    Only ONE of the five harvested specs declares securitySchemes at all (the FAA SAS
    API). The FAA PRD API sends its credentials as ordinary header PARAMETERS with no
    securityScheme and no security requirement, which is why a mechanical derive over
    securitySchemes alone misses it. Both are recorded below.
anonymous_surfaces:
- api: us-dot:faa-airport-status-web-service
  verified: '2026-07-28'
  evidence: 'GET https://external-api.faa.gov/asws/api/airport/status/JFK -> 200'
- api: us-dot:faa-aeronautic-product-release-api
  verified: '2026-07-28'
  evidence: 'GET https://external-api.faa.gov/apra/nfdc/nasr/info -> 200'
- api: us-dot:dot-data-hub-soda-api
  verified: '2026-07-28'
  note: Optional app token only; not authentication.
- api: us-dot:bts-open-data-soda-api
  verified: '2026-07-28'
- api: us-dot:faa-data-catalog-ckan-api
  verified: '2026-07-28'
  evidence: 'GET https://catalog.data.faa.gov/api/3/action/package_list -> 200'
- api: us-dot:nhtsa-vpic-api
  verified: '2026-07-28'
  evidence: 'GET https://vpic.nhtsa.dot.gov/api/vehicles/getallmakes?format=json -> 200, 12,306 makes'
- api: us-dot:nhtsa-safety-api
  verified: '2026-07-28'
  evidence: 'GET https://api.nhtsa.gov/complaints/complaintsByVehicle?make=honda&model=accord&modelYear=2020 -> 200'
schemes:
- name: apiKey
  type: apiKey
  in: header
  parameter: X-API-KEY
  applies_to: us-dot:faa-safety-assurance-system-api
  sources:
  - openapi/us-dot-faa-safety-assurance-system-api-openapi.yml
  note: >-
    Declared as a securityScheme but NOT applied — the spec has no top-level or
    operation-level `security` block, so generated clients omit it and get a gateway 401.
- name: appId
  type: apiKey
  in: header
  parameter: X-APP-ID
  applies_to: us-dot:faa-safety-assurance-system-api
  sources:
  - openapi/us-dot-faa-safety-assurance-system-api-openapi.yml
  note: Required alongside X-API-KEY. Same non-application problem.
- name: clientIdHeader
  type: apiKey
  in: header
  parameter: client_id
  applies_to: us-dot:faa-air-carrier-prd-api
  sources:
  - openapi/us-dot-faa-air-carrier-prd-api-openapi.yml
  note: >-
    Declared as a REQUIRED header parameter on every operation, not as a securityScheme.
    Paired with client_secret. An OAuth-shaped credential pair with no OAuth protocol —
    no token endpoint, no expiry, no scopes, no refresh.
- name: clientSecretHeader
  type: apiKey
  in: header
  parameter: client_secret
  applies_to: us-dot:faa-air-carrier-prd-api
  sources:
  - openapi/us-dot-faa-air-carrier-prd-api-openapi.yml
- name: socrataAppToken
  type: apiKey
  in: header
  parameter: X-App-Token
  alternate:
    in: query
    parameter: $$app_token
  applies_to: [us-dot:dot-data-hub-soda-api, us-dot:bts-open-data-soda-api]
  optional: true
  docs: https://dev.socrata.com/docs/app-tokens.html
  note: >-
    NOT authentication. An application token identifies the calling application so
    Socrata can apply a per-application throttle instead of the shared anonymous pool.
    Every read works without it. Issued self-serve at
    https://data.transportation.gov/profile/edit/developer_settings.
- name: fmcsaWebKey
  type: apiKey
  in: query
  parameter: webKey
  applies_to: us-dot:fmcsa-qcmobile-api
  docs: https://mobile.fmcsa.dot.gov/QCDevsite/docs/apiAccess
  note: >-
    Free, self-serve — the only self-serve API credential in the department. Requires a
    Login.gov account to obtain. Login.gov is the federal OIDC identity provider, but it
    gates key ISSUANCE, not the API itself; FMCSA exposes no OIDC discovery document.
- name: fraWebServiceAccount
  type: http
  scheme: unspecified
  applies_to: us-dot:fra-safety-data-api
  docs: https://safetydata.fra.dot.gov/MasterWebService/FRASafetyDataAPIs.aspx
  note: >-
    A "web service account" requested by emailing RsisSupport@dot.gov. Two separate
    request types — one for the full Data Download service, one for the Lite API. Neither
    WSDL declares a WS-Security policy; the credential model is not published.
- name: odeOperatorDefined
  type: none
  applies_to: us-dot:its-jpo-ode-rest-api
  note: >-
    The ODE Swagger 2.0 document declares no securityDefinitions. Authentication is
    whatever the deploying operator puts in front of it. Given this API writes to physical
    roadside units, that absence is the finding.
credential_issuance:
- portal: https://api.faa.gov/s/
  covers: [us-dot:faa-air-carrier-prd-api, us-dot:faa-safety-assurance-system-api]
  self_serve: false
  gate: FAA operator accreditation (14 CFR Part 121/135/125/91K/Air Tour/Public Aircraft/91 Corporate for PRD)
  guide: https://www.faa.gov/regulationspolicies/pilotrecordsdatabase/air-carrier-api-discover-learn-get-access
- portal: https://mobile.fmcsa.dot.gov/QCDevsite/
  covers: [us-dot:fmcsa-qcmobile-api]
  self_serve: true
  identity: Login.gov
- portal: 'mailto:RsisSupport@dot.gov'
  covers: [us-dot:fra-safety-data-api]
  self_serve: false
- portal: https://data.transportation.gov/profile/edit/developer_settings
  covers: [us-dot:dot-data-hub-soda-api, us-dot:bts-open-data-soda-api]
  self_serve: true
  optional: true
oauth:
  supported: false
  evidence:
  - '/.well-known/oauth-authorization-server -> 404 on every DOT, BTS and FAA host probed 2026-07-28'
  - '/.well-known/openid-configuration -> 404 on every host probed'
  - No OpenAPI declares an oauth2 securityScheme
  consequence: >-
    No scopes/ artifact is emitted for this provider. There is no scope surface to
    describe — key-auth providers have no OAuth scope model, and forcing an empty
    artifact would be misleading.
transport:
  tls_minimum_observed: TLSv1.2
  detail: See security/us-dot-domain-security.yml.