generated: '2026-09-05' method: searched source: https://1token.tech/api/1ndex/v1/README.md spec_source: openapi/1token-1ndex-openapi.yml docs: https://1token.tech/api/1ndex/v1/README.md summary: types: [] anonymous: true api_key_in: [] oauth2_flows: [] note: >- The one public 1Token API declares no security schemes and an empty top-level `security: []`, and the published documentation states this explicitly: "No authentication is currently required." This is a documented anonymous-access posture, not a thin or missing spec — verified by an unauthenticated live GET returning HTTP 200 application/json on 2026-09-05. schemes: [] public_access: anonymous: true scope: >- Aggregate 1ndex strategy overview only. The published contract explicitly excludes customer-specific data, write operations, CAM product interfaces, and third-party APIs consumed by 1Token. evidence: - kind: spec detail: 'openapi/1token-1ndex-openapi.yml: top-level `security: []` and operation-level `security: []`' - kind: docs url: https://1token.tech/api/1ndex/v1/README.md detail: '"No authentication is currently required."' - kind: probe url: https://1ndex.1token.tech/api/v1/public/strategy-overview?strategy_type=DeltaNeutral http_status: 200 detail: unauthenticated request returned 200 application/json gated_surfaces: - name: 1Token CAM auth: customer login url: https://1token.tech/cam-docs note: >- CAM technical API documentation redirects to https://1token.tech/cam-docs-login and is disallowed in robots.txt. The Trust Center describes API key management, RBAC, MFA and read-only API integrations for CAM, but no CAM auth reference is public. - name: 1ndex application auth: account login url: https://1ndex.1token.tech/login note: The 1ndex web app requires an account; access is requested via a Calendly link.