generated: '2026-09-19' method: searched source: openapi/airmdr-case-manager-openapi.yml, openapi/airmdr-user-management-service-openapi.yml docs: https://docs.airmdr.com/api-reference/apitoken summary: types: - apiKey api_key_in: - cookie oauth2: false oidc: false schemes: - name: SessionCookie type: apiKey in: cookie parameter: Session usage: 'curl --location https://app.airmdr.com/airmdrapi/organization --header ''Cookie: Session=""''' token_lifecycle: issued_by: Admin dashboard → API Tokens → Create API Token (Admin or Super Admin role required); also createAPITokenForUserAPI (POST /users/tokens) and createAPITokenForSlackWorkflowAPI shown_once: true listing: listTokensForUserAPI (GET /users/tokens) revocation: delete the token in the dashboard or deleteTokenAPI (DELETE /users/tokens/{token_id}) expiry: tokens can expire; docs advise handling 401 Unauthorized by checking for token expiration and prefer "scoped and expiring tokens" (no scope vocabulary is published) sources: - openapi/airmdr-case-manager-openapi.yml - openapi/airmdr-user-management-service-openapi.yml - name: WebhookURLSecret type: url-path-secret in: path parameter: '{webhook_id}/{secret}' operation: createAlertFromWebhookAPI (POST /webhooks/{webhook_id}/{secret}/alerts) usage: authenticated purely by webhook_id + secret embedded in the URL path; 404 on unknown id or invalid secret sources: - openapi/airmdr-case-manager-openapi.yml note: not a securityScheme in the spec; documented in the operation description and the M28.1 release notes context_headers: required: [User-ID, Organization-ID] optional: [X-Request-ID, Execution-ID, Organization-Hosturl] note: the docs say these are "automatically preloaded" into request examples when a token is generated console_sso: providers: [Azure AD, Google, Okta] docs: https://docs.airmdr.com/essentials/SSO-Overview note: console user sign-in only; not an API authentication surface