Zefr · Authentication Profile
Zefr Authentication
Authentication
Zefr declares 2 security scheme(s) across its OpenAPI definitions.
CompanyAdTechBrand SafetyBrand SuitabilityContent IntelligenceContent ModerationVideoSocial-MediaAdvertisingMedia MeasurementMachine-Learning
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
openIdConnect
oauth2
· flows: , ,
Source
Authentication Profile
generated: '2026-08-12'
method: probed
source: https://login.zefr.com/.well-known/openid-configuration
note: >-
Zefr publishes no developer portal, no API reference and no OpenAPI, so there is no
securityScheme block to derive from. What IS published, anonymously and machine-readably,
is the OpenID Connect discovery document for Zefr's own identity provider — an Auth0
tenant on the custom domain login.zefr.com (CNAME zefr-prod-cd-qq34zjzlcmyzcxao.edge.tenants.auth0.com)
that authenticates the Zefr Brand Suitability Suite at suitability.zefr.com. This profile is
read verbatim from that document. It describes how Zefr authenticates identities; it does NOT
describe how a customer authenticates against the production API gateway at api.zefr.com,
which Zefr does not document publicly.
issuer: https://login.zefr.com/
provider: Auth0 (custom domain)
schemes:
- id: openIdConnect
type: openIdConnect
openIdConnectUrl: https://login.zefr.com/.well-known/openid-configuration
description: >-
OpenID Connect 1.0 discovery is served anonymously. Authorization Code with PKCE
(S256) is supported, as is the client_credentials grant — the grant a machine-to-machine
API client would use.
- id: oauth2
type: oauth2
description: OAuth 2.0 Authorization Server Metadata (RFC 8414) at the same issuer.
flows:
authorizationCode:
authorizationUrl: https://login.zefr.com/authorize
tokenUrl: https://login.zefr.com/oauth/token
refreshUrl: https://login.zefr.com/oauth/token
clientCredentials:
tokenUrl: https://login.zefr.com/oauth/token
deviceCode:
deviceAuthorizationUrl: https://login.zefr.com/oauth/device/code
tokenUrl: https://login.zefr.com/oauth/token
endpoints:
authorization: https://login.zefr.com/authorize
token: https://login.zefr.com/oauth/token
userinfo: https://login.zefr.com/userinfo
jwks: https://login.zefr.com/.well-known/jwks.json
revocation: https://login.zefr.com/oauth/revoke
registration: https://login.zefr.com/oidc/register
device_authorization: https://login.zefr.com/oauth/device/code
backchannel_authentication: https://login.zefr.com/bc-authorize
mfa_challenge: https://login.zefr.com/mfa/challenge
global_token_revocation: https://login.zefr.com/oauth/global-token-revocation/connection/{connectionName}
grant_types_supported:
- client_credentials
- authorization_code
- refresh_token
- password
- implicit
- urn:ietf:params:oauth:grant-type:device_code
- urn:ietf:params:oauth:grant-type:token-exchange
- urn:ietf:params:oauth:grant-type:jwt-bearer
- http://auth0.com/oauth/grant-type/password-realm
- http://auth0.com/oauth/grant-type/passwordless/otp
- http://auth0.com/oauth/grant-type/mfa-oob
- http://auth0.com/oauth/grant-type/mfa-otp
- http://auth0.com/oauth/grant-type/mfa-recovery-code
token_endpoint_auth_methods_supported:
- client_secret_basic
- client_secret_post
- private_key_jwt
- none
pkce:
supported: true
code_challenge_methods:
- S256
- plain
id_token_signing_alg_values_supported:
- HS256
- RS256
- PS256
dpop:
supported: true
signing_alg_values:
- ES256
mfa:
supported: true
challenge_endpoint: https://login.zefr.com/mfa/challenge
note: MFA grant types (mfa-oob, mfa-otp, mfa-recovery-code) are advertised.
backchannel_logout:
supported: true
session_supported: true
dynamic_client_registration:
supported: true
endpoint: https://login.zefr.com/oidc/register
note: Advertised by the discovery document; not verified (registration was not attempted).
api_key_auth:
documented: false
note: >-
No public documentation describes an API key, bearer token or signing scheme for
api.zefr.com. The gateway (Apigee) answers every anonymous request with a
messaging.adaptors.http.flow.ApplicationNotFound fault, so no auth challenge is observable.
gaps:
- No public API reference documents how to authenticate against api.zefr.com.
- No audience/resource identifier is published for a Zefr product API.
- No scope reference page exists; only the standard OIDC identity scopes are advertised.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zefr-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.