viagogo · Authentication Profile
Viagogo Authentication
Authentication
viagogo secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, clientCredentials, implicit, and refreshToken flow(s).
CompanyTicketingEventMarketplaceEntertainmentSecondary MarketCommerceTravel And Leisure
Methods: oauth2
Schemes: 1
OAuth flows: authorizationCode, clientCredentials, implicit, refreshToken
API key in:
Security Schemes
OAuth2 oauth2
· flows: implicit, clientCredentials, authorizationCode
Source
Authentication Profile
generated: '2026-08-05'
method: searched
source: https://developer.viagogo.net/docs/authentication/
docs: https://developer.viagogo.net/docs/authentication/
derived_from:
- openapi/viagogo-account.json
- openapi/viagogo-catalog.json
- openapi/viagogo-inventory.json
- openapi/viagogo-sales.json
- openapi/viagogo-webhooks.json
x-evidence:
- url: https://raw.githubusercontent.com/viagogo/viagogo-api-docs/main/docs/authentication/basic-steps.md
http_status: 200
fetched: '2026-08-05'
- url: https://account.viagogo.com/.well-known/openid-configuration
http_status: 200
fetched: '2026-08-05'
- url: https://sandbox.account.viagogo.com/.well-known/openid-configuration
http_status: 200
fetched: '2026-08-05'
- url: https://api.viagogo.net/v2/user
http_status: 401
fetched: '2026-08-05'
note: An unauthenticated call to the API returns 401 as documented.
summary:
model: oauth2
types:
- oauth2
oauth2_flows:
- authorizationCode
- clientCredentials
- implicit
- refreshToken
token_placement: 'Authorization: Bearer <access_token>'
api_keys: false
mutual_tls: false
statement: "The viagogo API uses OAuth2 for all authentication. All API requests
must be authenticated or you will receive a 401 Unauthorized error response."
schemes:
- name: OAuth2
type: oauth2
bearerFormat: JWT
flows:
- flow: implicit
authorizationUrl: https://account.viagogo.com/authorize
tokenUrl: https://account.viagogo.com/oauth2/token
refreshUrl: https://account.viagogo.com/oauth2/token
scopes_in_spec: 0
- flow: clientCredentials
tokenUrl: https://account.viagogo.com/oauth2/token
scopes_in_spec: 0
- flow: authorizationCode
authorizationUrl: https://account.viagogo.com/authorize
tokenUrl: https://account.viagogo.com/oauth2/token
refreshUrl: https://account.viagogo.com/oauth2/token
scopes_in_spec: 0
applied_to_operations: 89
operations_without_security: 1
note: >-
The oauth2 securityScheme is declared with empty `scopes` maps in all five specs;
the required scopes are carried per-operation in the `security` requirement
arrays instead. See scopes/viagogo-scopes.yml for the full 17-scope union.
sources:
- openapi/viagogo-account.json
- openapi/viagogo-catalog.json
- openapi/viagogo-inventory.json
- openapi/viagogo-sales.json
- openapi/viagogo-webhooks.json
flows_documented:
- name: Application-Only Authentication Flow
grant_type: client_credentials
docs: https://developer.viagogo.net/docs/authentication/application-only-authentication-flow
use_case: Access public, non-user-specific data such as categories, events, venues
and listings.
client_authentication: HTTP Basic — base64(url-encoded client_id ":" url-encoded
client_secret) per RFC 1738
issues_refresh_token: false
note: Refresh tokens are not issued by the Application-Only Flow; the application
must re-authenticate to obtain new access tokens.
- name: User-Login Authentication Flow
grant_type: authorization_code
docs: https://developer.viagogo.net/docs/authentication/user-login-authentication-flow
use_case: Manage user-specific data such as payment methods, listings, purchases
and sales.
issues_refresh_token: true
- name: Token Refresh
grant_type: refresh_token
docs: https://developer.viagogo.net/docs/authentication/token-expiration
note: Refresh tokens are single-use and long-lived; access tokens are short-lived.
Token responses carry `expires_in` (seconds) and the granted `scope`.
authorization_server:
issuer: https://account.viagogo.com/
discovery: https://account.viagogo.com/.well-known/openid-configuration
authorization_endpoint: https://account.viagogo.com/authorize
token_endpoint: https://account.viagogo.com/oauth2/token
jwks_uri: https://account.viagogo.com/.well-known/jwks
grant_types_supported:
- client_credentials
- tools
- impersonation
- refresh_token
- authorization_code
- implicit
- password
token_endpoint_auth_methods_supported:
- client_secret_post
- private_key_jwt
- client_secret_basic
code_challenge_methods_supported:
- plain
- S256
id_token_signing_alg_values_supported:
- RS256
sandbox_issuer: https://sandbox.account.viagogo.com/
sandbox_discovery: https://sandbox.account.viagogo.com/.well-known/openid-configuration
credential_acquisition:
self_serve: false
method: Client ID and Client Secret are issued by viagogo per application; the docs
direct developers to developer.viagogo.net to obtain OAuth2 credentials. There
is no public self-service key issuance page.
note: viagogo states that Client ID, Client Secret and all access tokens "should
be considered as sensitive as passwords and should not be shared."
error_signals:
- status: 401
code: null
meaning: Authentication credentials were missing or incorrect.
- status: 403
code: insufficient_scope
meaning: The access token used in the request does not have the scope required to
access this resource.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/viagogo-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.