generated: '2026-08-06' method: probed source: https://avenueone.us.auth0.com/.well-known/openid-configuration note: >- Avenue One publishes no OpenAPI, so there are no securitySchemes to derive from. This profile is probed from the only publicly readable authentication surface the company exposes: the Auth0 tenant that fronts the Partner Portal. It describes how humans sign in to AvenueOS — it is NOT a documented developer authentication model, and Avenue One does not publish one. applies_to: >- Partner Portal (partners.avenueone.com) and the AvenueOS product hosts (credit.avenueone.com and its app/builder/investor portals). schemes: - name: auth0-oidc type: openIdConnect protocol: OpenID Connect 1.0 / OAuth 2.0 provider: Auth0 issuer: https://avenueone.us.auth0.com/ openid_configuration: https://avenueone.us.auth0.com/.well-known/openid-configuration jwks_uri: https://avenueone.us.auth0.com/.well-known/jwks.json authorization_endpoint: https://avenueone.us.auth0.com/authorize token_endpoint: https://avenueone.us.auth0.com/oauth/token userinfo_endpoint: https://avenueone.us.auth0.com/userinfo revocation_endpoint: https://avenueone.us.auth0.com/oauth/revoke device_authorization_endpoint: https://avenueone.us.auth0.com/oauth/device/code registration_endpoint: https://avenueone.us.auth0.com/oidc/register flows: - authorization_code - implicit - client_credentials - refresh_token - device_code pkce: supported: true code_challenge_methods: - S256 - plain mfa: challenge_endpoint: https://avenueone.us.auth0.com/mfa/challenge scopes_supported: - openid - profile - offline_access - name - given_name - family_name - nickname - email - email_verified - picture - created_at - identities - phone - address observed_login_request: note: >- Scopes and role gate observed in the 302 Location header that partners.avenueone.com issues to the Auth0 tenant. scope: openid profile email groups required_role: Partner Portal response_type: code redirect_uri: https://partners.avenueone.com/oauth2/idpresponse edge: 'AWS ALB OIDC authentication in front of CloudFront (server: awselb/2.0)' developer_authentication: documented: false api_keys: false public_docs: false note: >- No developer portal, API key issuance, or published authentication guide was found on any Avenue One host. Access to AvenueOS requires a partner/investor account provisioned by Avenue One. x-evidence: - url: https://partners.avenueone.com/ http_status: 302 checked: '2026-08-06' note: 302 to the Auth0 universal login (avenueone.us.auth0.com) - url: https://avenueone.us.auth0.com/.well-known/openid-configuration http_status: 200 content_type: application/json; charset=utf-8 checked: '2026-08-06' - url: https://avenueone.us.auth0.com/.well-known/jwks.json http_status: 200 checked: '2026-08-06'