generated: '2026-09-09' method: searched source: >- npm derrick-mcp@0.3.0 (dist/api.js, dist/config.js) + https://app1.derrick-app.com/.well-known/oauth-authorization-server + https://app1.derrick-app.com/.well-known/oauth-protected-resource/mcp + live 401 probes of https://app1.derrick-app.com/api/v1/openapi.json and https://app1.derrick-app.com/mcp note: >- No OpenAPI securitySchemes exist (no OpenAPI is published); this profile is read from the provider's own npm client code, its RFC 8414/9728 discovery documents, and live unauthenticated probes. API keys are issued in the Google Sheets add-on (Derrick menu > API) and require a paid plan (see plans artifact for the Standard-vs-Plus gate discrepancy). schemes: - name: api_key_header type: apiKey in: header header: X-API-Key surfaces: [REST API] description: >- The derrick-mcp package sends the API key as an X-API-Key header on every https://app1.derrick-app.com/api/v1/* call. Anonymous requests return 401 {"success":false,"error":"Invalid or missing API key","errorType":"AUTH"} (probed 2026-09-09). - name: bearer_api_key type: http scheme: bearer surfaces: [MCP remote endpoint] description: >- The MCP server card documents Authorization: Bearer on https://app1.derrick-app.com/mcp; required_at_install is false - the server prompts for a key on the first tool call. - name: oauth2_authorization_code type: oauth2 surfaces: [MCP remote endpoint] flows: authorizationCode: authorizationUrl: https://app1.derrick-app.com/authorize tokenUrl: https://app1.derrick-app.com/token refreshUrl: https://app1.derrick-app.com/token scopes: {} pkce: S256 dynamic_client_registration: https://app1.derrick-app.com/register revocation: https://app1.derrick-app.com/revoke description: >- RFC 8414 authorization-server metadata served at /.well-known/oauth-authorization-server (probed 200, 2026-09-09); grants authorization_code + refresh_token, token_endpoint_auth client_secret_post or none, PKCE S256 only. The MCP endpoint's WWW-Authenticate challenge points at RFC 9728 resource metadata /.well-known/oauth-protected-resource/mcp. No scopes are published (scopes are not defined in the metadata and no scopes reference page exists). environment_keys: - DERRICK_API_KEY