Wayflyer · Authentication Profile
Wayflyer Authentication
Authentication
Authentication profile for the Wayflyer Embedded Finance (Hosted Capital) API. Two-tier bearer-JWT model: partners exchange a backend-only client_id/client_secret for a Partner Token, then mint per-merchant Company Tokens that are forwarded to the frontend for SDK / API calls. Both token classes appear in the OpenAPI as http bearer securitySchemes (PartnerToken, CompanyToken). No OAuth2/OIDC flows and no API-key scheme; the sandbox environment uses a separate sandbox client_id/secret.
Wayflyer secures its APIs with http across 2 declared security schemes, as derived from its OpenAPI definitions.
CompanyEcommerceFintechEmbedded FinanceLendingRevenue-Based FinancingFinancing
Methods: http
Schemes: 2
OAuth flows:
API key in:
Security Schemes
CompanyToken http
PartnerToken http