Commune · Authentication Profile

Usecommune Authentication

Authentication

Commune secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

NewslettersEmailCommunityPublishingCreator EconomySubscribersWebhooksMCPAnalyticsContent
Methods: http, oauth2 Schemes: 2 OAuth flows: authorizationCode API key in:

Security Schemes

oauth2 oauth2
· flows: authorizationCode
apiKey http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-10-07'
method: searched
source: openapi/usecommune-openapi.yml; https://usecommune.dev/use-cases/build-an-integration; https://usecommune.dev/guides/getting-started;
  https://api.usecommune.com/.well-known/oauth-protected-resource; https://usecommune.com/.well-known/oauth-authorization-server
summary:
  types:
  - http
  - oauth2
  oauth2_flows:
  - authorizationCode
schemes:
- name: oauth2
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://usecommune.com/api/oauth/authorize
    tokenUrl: https://usecommune.com/api/oauth/token
    scopes: 13
  description: 'An OAuth access token, sent as `Authorization: Bearer <token>`. The

    walkthrough of the whole flow is at

    [usecommune.dev/use-cases/build-an-integration](https://usecommune.dev/use-cases/build-an-integration):

    discovery, registration, PKCE, the consent screen, the exchange, refresh

    and revocation.


    Ask for a family scope and the person picks which newsletter

    the token reaches; ask for `account:read`'
  sources:
  - openapi/usecommune-openapi.yml
- name: apiKey
  type: http
  scheme: bearer
  bearerFormat: Commune API key
  description: 'A Commune API key, sent as `Authorization: Bearer <key>`. A key is

    granted one or more newsletters and carries six permission families on

    each, every one of them `none`, `read` or `write`. An operation names

    the family and the level it needs.


    A key is minted by a creator in Commune''s settings: no flow, no consent

    screen, no expiry. That is the whole difference from `oauth2`. An

    operation that dec'
  sources:
  - openapi/usecommune-openapi.yml
docs: https://usecommune.dev/use-cases/build-an-integration
discovery:
  rfc9728_protected_resource: https://api.usecommune.com/.well-known/oauth-protected-resource (200)
  rfc8414_authorization_server: https://usecommune.com/.well-known/oauth-authorization-server (200)
  www_authenticate_on_401: Bearer realm="Commune API", resource_metadata="https://api.usecommune.com/.well-known/oauth-protected-resource"
  dynamic_client_registration: https://usecommune.com/api/oauth/register (RFC 7591, token_endpoint_auth_method none
    supported)
  pkce: S256 required for public clients
  refresh: refresh_token grant; offline_access scope
api_keys:
  prefix: cmn_sk_
  minted_at: https://usecommune.com/settings/api-keys
  expiry: none; revocable via DELETE /api-keys/{key} or in settings
  grant: per newsletter, six families each none/read/write, plus optional account:read
permission_model:
  families:
  - content
  - audience
  - sending
  - insights
  - settings
  - webhooks
  levels:
  - none
  - read
  - write
  separate_axis: account:read
  enforcement: 403 forbidden / insufficient_scope naming what was needed and what the credential holds

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/usecommune-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.