Wingtra · Authentication Profile

Wingtra Authentication

Authentication

Wingtra declares 3 security scheme(s) across its OpenAPI definitions.

CompanyDronesUAVAerial SurveyingMappingPhotogrammetryGeospatialSurveyingLiDARHardwareSwitzerland
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

openIdConnect
http
scheme: bearer
unknown

Source

Authentication Profile

wingtra-authentication.yml Raw ↑
generated: '2026-09-04'
method: probed
source:
- https://my-wingtra.eu.auth0.com/.well-known/openid-configuration
- https://portal.wingtra.com/
- https://api.my.wingtra.com/graphql
- graphql/wingtra-my-portal.graphql
docs: null
summary: >-
  Wingtra publishes no authentication documentation for developers, because it issues no
  developer credentials. Everything below was established by probing surfaces that answer
  anonymously. Human sign-in across the Wingtra estate is Auth0 — the tenant
  my-wingtra.eu.auth0.com, named by portal.wingtra.com's own 302 to
  /authorize?client_id=...&scope=openid%20profile%20email&response_type=code with PKCE
  S256. Machine access to the portal GraphQL API is a bearer access token minted by that
  tenant, or by the API's own `login` mutation, which returns an OAuth-shaped token
  envelope directly.
schemes:
- id: auth0-oidc
  type: openIdConnect
  surfaces: [portal.wingtra.com, my.wingtra.com, cloud.wingtra.com]
  issuer: https://my-wingtra.eu.auth0.com/
  discovery: https://my-wingtra.eu.auth0.com/.well-known/openid-configuration
  authorization_endpoint: https://my-wingtra.eu.auth0.com/authorize
  token_endpoint: https://my-wingtra.eu.auth0.com/oauth/token
  userinfo_endpoint: https://my-wingtra.eu.auth0.com/userinfo
  revocation_endpoint: https://my-wingtra.eu.auth0.com/oauth/revoke
  jwks_uri: https://my-wingtra.eu.auth0.com/.well-known/jwks.json
  flow: authorization_code with PKCE (S256)
  pkce_methods: [S256, plain]
  grant_types:
  - authorization_code
  - refresh_token
  - client_credentials
  - password
  - implicit
  - urn:ietf:params:oauth:grant-type:device_code
  - urn:ietf:params:oauth:grant-type:token-exchange
  - urn:ietf:params:oauth:grant-type:jwt-bearer
  id_token_signing_algs: [RS256, PS256, HS256]
  token_endpoint_auth_methods: [client_secret_basic, client_secret_post, private_key_jwt, none]
  mfa: >-
    The tenant advertises /mfa/challenge and the mfa-oob, mfa-otp and mfa-recovery-code
    grants, so MFA is available; whether it is enforced for a given Wingtra account is not
    observable anonymously.
  dynamic_registration:
    endpoint: https://my-wingtra.eu.auth0.com/oidc/register
    note: >-
      Advertised in the discovery document. Advertisement is not an invitation — Wingtra
      does not offer third-party API clients, and this endpoint was not exercised.
  scopes: scopes/wingtra-scopes.yml
- id: portal-graphql-bearer
  type: http
  scheme: bearer
  surface: https://api.my.wingtra.com/graphql
  bearer_format: JWT
  detail: >-
    The schema's `login` mutation returns LoginResponse { access_token, refresh_token,
    token_type, expires_in, scope, assigned_roles, user_info }, and `refreshToken` renews
    it — an OAuth-shaped envelope handed back over GraphQL. Authenticated calls carry the
    access token as a bearer credential. The User type mirrors an Auth0 profile
    (user_id, identities[].provider, app_metadata.tenantId), which is what ties this API
    to the Auth0 tenant above.
  roles:
    field: assigned_roles
    note: Role names are returned per user; no public list of roles is published.
- id: sky-rest-unknown
  type: unknown
  surface: https://api.sky.wingtra.com
  detail: >-
    Not determinable anonymously. Every unauthenticated request to this host, including the
    /v1 paths its own web client calls, is answered HTTP 400 "Something went wrong." by an
    edge in front of the application — not 401, not WWW-Authenticate. The schema's
    `getSkyToken` query and the client's Auth0 session together indicate a bearer token
    minted from the same tenant, but no anonymous probe confirms the scheme, so it is
    recorded as unknown rather than assumed.
anonymous_access:
  graphql_introspection:
    open: true
    endpoint: https://api.my.wingtra.com/graphql
    verified: '2026-09-04'
    http_status: 200
    detail: >-
      __schema answers unauthenticated callers in full. Field resolvers were NOT exercised;
      only the introspection meta-field was queried. This is a posture finding worth
      reporting to Wingtra — production GraphQL services normally disable introspection —
      and it is the only reason this repository can describe the API at all.
  cors:
    access_control_allow_origin: '*'
    access_control_allow_credentials: 'true'
    note: >-
      Observed on the live 200. `*` together with allow-credentials is a combination
      browsers reject, so it is recorded as observed rather than interpreted.
findings_for_provider:
- Anonymous GraphQL introspection is enabled on the production api.my.wingtra.com endpoint.
- No security.txt is served on any Wingtra host, so there is no published route for the above.
x-evidence:
  fetched: '2026-09-04'
  probes:
  - {url: 'https://my-wingtra.eu.auth0.com/.well-known/openid-configuration', http_status: 200}
  - {url: 'https://portal.wingtra.com/', http_status: 302, note: 'redirects to my-wingtra.eu.auth0.com/authorize'}
  - {url: 'https://api.my.wingtra.com/graphql', http_status: 200, note: 'anonymous introspection succeeded'}
  - {url: 'https://api.sky.wingtra.com/v1/sites', http_status: 400}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/wingtra-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.