viagogo · Authentication Profile

Viagogo Authentication

Authentication

viagogo secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, clientCredentials, implicit, and refreshToken flow(s).

CompanyTicketingEventMarketplaceEntertainmentSecondary MarketCommerceTravel And Leisure
Methods: oauth2 Schemes: 1 OAuth flows: authorizationCode, clientCredentials, implicit, refreshToken API key in:

Security Schemes

OAuth2 oauth2
· flows: implicit, clientCredentials, authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-08-05'
method: searched
source: https://developer.viagogo.net/docs/authentication/
docs: https://developer.viagogo.net/docs/authentication/
derived_from:
- openapi/viagogo-account.json
- openapi/viagogo-catalog.json
- openapi/viagogo-inventory.json
- openapi/viagogo-sales.json
- openapi/viagogo-webhooks.json
x-evidence:
- url: https://raw.githubusercontent.com/viagogo/viagogo-api-docs/main/docs/authentication/basic-steps.md
  http_status: 200
  fetched: '2026-08-05'
- url: https://account.viagogo.com/.well-known/openid-configuration
  http_status: 200
  fetched: '2026-08-05'
- url: https://sandbox.account.viagogo.com/.well-known/openid-configuration
  http_status: 200
  fetched: '2026-08-05'
- url: https://api.viagogo.net/v2/user
  http_status: 401
  fetched: '2026-08-05'
  note: An unauthenticated call to the API returns 401 as documented.
summary:
  model: oauth2
  types:
  - oauth2
  oauth2_flows:
  - authorizationCode
  - clientCredentials
  - implicit
  - refreshToken
  token_placement: 'Authorization: Bearer <access_token>'
  api_keys: false
  mutual_tls: false
  statement: "The viagogo API uses OAuth2 for all authentication. All API requests
    must be authenticated or you will receive a 401 Unauthorized error response."
schemes:
- name: OAuth2
  type: oauth2
  bearerFormat: JWT
  flows:
  - flow: implicit
    authorizationUrl: https://account.viagogo.com/authorize
    tokenUrl: https://account.viagogo.com/oauth2/token
    refreshUrl: https://account.viagogo.com/oauth2/token
    scopes_in_spec: 0
  - flow: clientCredentials
    tokenUrl: https://account.viagogo.com/oauth2/token
    scopes_in_spec: 0
  - flow: authorizationCode
    authorizationUrl: https://account.viagogo.com/authorize
    tokenUrl: https://account.viagogo.com/oauth2/token
    refreshUrl: https://account.viagogo.com/oauth2/token
    scopes_in_spec: 0
  applied_to_operations: 89
  operations_without_security: 1
  note: >-
    The oauth2 securityScheme is declared with empty `scopes` maps in all five specs;
    the required scopes are carried per-operation in the `security` requirement
    arrays instead. See scopes/viagogo-scopes.yml for the full 17-scope union.
  sources:
  - openapi/viagogo-account.json
  - openapi/viagogo-catalog.json
  - openapi/viagogo-inventory.json
  - openapi/viagogo-sales.json
  - openapi/viagogo-webhooks.json
flows_documented:
- name: Application-Only Authentication Flow
  grant_type: client_credentials
  docs: https://developer.viagogo.net/docs/authentication/application-only-authentication-flow
  use_case: Access public, non-user-specific data such as categories, events, venues
    and listings.
  client_authentication: HTTP Basic — base64(url-encoded client_id ":" url-encoded
    client_secret) per RFC 1738
  issues_refresh_token: false
  note: Refresh tokens are not issued by the Application-Only Flow; the application
    must re-authenticate to obtain new access tokens.
- name: User-Login Authentication Flow
  grant_type: authorization_code
  docs: https://developer.viagogo.net/docs/authentication/user-login-authentication-flow
  use_case: Manage user-specific data such as payment methods, listings, purchases
    and sales.
  issues_refresh_token: true
- name: Token Refresh
  grant_type: refresh_token
  docs: https://developer.viagogo.net/docs/authentication/token-expiration
  note: Refresh tokens are single-use and long-lived; access tokens are short-lived.
    Token responses carry `expires_in` (seconds) and the granted `scope`.
authorization_server:
  issuer: https://account.viagogo.com/
  discovery: https://account.viagogo.com/.well-known/openid-configuration
  authorization_endpoint: https://account.viagogo.com/authorize
  token_endpoint: https://account.viagogo.com/oauth2/token
  jwks_uri: https://account.viagogo.com/.well-known/jwks
  grant_types_supported:
  - client_credentials
  - tools
  - impersonation
  - refresh_token
  - authorization_code
  - implicit
  - password
  token_endpoint_auth_methods_supported:
  - client_secret_post
  - private_key_jwt
  - client_secret_basic
  code_challenge_methods_supported:
  - plain
  - S256
  id_token_signing_alg_values_supported:
  - RS256
  sandbox_issuer: https://sandbox.account.viagogo.com/
  sandbox_discovery: https://sandbox.account.viagogo.com/.well-known/openid-configuration
credential_acquisition:
  self_serve: false
  method: Client ID and Client Secret are issued by viagogo per application; the docs
    direct developers to developer.viagogo.net to obtain OAuth2 credentials. There
    is no public self-service key issuance page.
  note: viagogo states that Client ID, Client Secret and all access tokens "should
    be considered as sensitive as passwords and should not be shared."
error_signals:
- status: 401
  code: null
  meaning: Authentication credentials were missing or incorrect.
- status: 403
  code: insufficient_scope
  meaning: The access token used in the request does not have the scope required to
    access this resource.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/viagogo-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.