generated: '2026-09-05' method: searched source: >- https://raw.githubusercontent.com/9flats/nineflats-api/master/lib/nineflats-api/client.rb, https://raw.githubusercontent.com/9flats/nineflats-api/master/lib/nineflats-api/requests.rb, https://raw.githubusercontent.com/9flats/nineflats-api/master/nineflats-api.gemspec description: >- The 9flats API v1 authentication model, read from 9flats' OWN published client library (github.com/9flats/nineflats-api) rather than from documentation — the documentation site the gem links to, http://9flats.github.com/api_docs/, now returns 404, so the provider's source code is the only first-party statement of the auth model still reachable. No auth page, no OpenAPI securitySchemes and no OAuth discovery document were retrievable: every path on www.9flats.com, 9flats.com and api.9flats.com is behind a Cloudflare managed challenge (403). schemes: - id: oauth1 type: oauth1 label: OAuth 1.0a (three-legged) in: header evidence: >- client.rb constructs ::OAuth::Consumer.new(api_key, api_secret, site: "http://www.9flats.com", scheme: :header, http_method: :post) and exposes request_token(callback_url) -> get_request_token(oauth_callback: ...) and exchange_access_token(request_token, verifier) -> get_access_token(oauth_verifier: ...). The gemspec declares a runtime dependency on the `oauth` gem. credentials: - name: api_key role: OAuth consumer key - name: api_secret role: OAuth consumer secret flow: - Obtain a request token with an oauth_callback. - Send the user to 9flats to authorize. - Exchange the request token plus oauth_verifier for an access token. signature_transport: Authorization header (scheme :header) required_for: - GET /api/v1/users/{user_id}/bookings optional_for: - GET /api/v1/places/{slug} - GET /api/v1/users/{user_id} note: >- OAuth 1.0a, not OAuth 2.0 — there is no token endpoint, no scopes, no refresh token and no OpenID Connect surface, so scopes/ is deliberately not emitted for this provider. - id: client_id type: apiKey in: query name: client_id label: Consumer key echoed as a client_id query parameter evidence: >- Every request in requests.rb appends QueryStringNormalizer.normalize({client_id: consumer.key}) to the path, e.g. GET /api/v1/places/{slug}?client_id=... note: >- This is the same value as the OAuth consumer key, carried a second time in the query string. Read-only endpoints are called with the unauthenticated consumer (consumer.request) and this parameter; only user bookings require an access token. unauthenticated_access: available: true note: >- Search, place detail, photos, prices, reviews, calendar, user profile and user favourites are fetched through consumer.request without an access token — signed with the consumer credentials only. A client_id is still required, so there is no anonymous surface. authorization_gate: evidence: >- requests.rb raises Nineflats::NotAuthenticatedException("User is not authenticated yet!") before calling /api/v1/users/{id}/bookings when Client.client.authorized? is false. verification: live_probe_attempted: true live_probe_result: >- Could not verify against the running service. GET https://www.9flats.com/api/v1/places returned 403 with cf-mitigated: challenge on 2026-09-05, as did every other path on every 9flats host. caveat: >- This profile describes API v1 as of the last release of the provider's SDK (0.0.9, 2011-11-07). A v3 surface existed at https://www.9flats.com/api/v3/places/ per the provider's own (now removed) api_docs site; its auth model is unknown and is NOT asserted here. contact: api@9flats.com