generated: '2026-09-10' method: searched source: openapi/fraud-net-public-apis-openapi.json docs: https://api-docs.fraud.net/docs/public-apis/b2edb775739e6-api-documentation provider: Fraud.net providerId: fraud-net summary: types: [http] http_schemes: [basic] api_key_in: [] oauth2_flows: [] scopes_published: false mtls: false schemes: - name: basic-auth type: http scheme: basic applied: global description: >- HTTP Basic Access Authentication. The API key issued by Fraud.net is supplied as the credential pair, base64-encoded and sent as `Authorization: Basic `. The provider's own security scheme spells out the four RFC 7617 construction steps. sources: - openapi/fraud-net-public-apis-openapi.json - https://api-docs.fraud.net/docs/public-apis/b2edb775739e6-api-documentation credential_issuance: method: portal where: >- "You can find or generate your API key in the Developer section of the Fraud.net Case Management Portal." — provider API documentation, Authentication section. self_service: false note: >- There is no public sign-up that yields a key. The portal is reached after a commercial onboarding (https://www.fraud.net/demo-request), so key issuance is sales-gated even though the contract and documentation are fully public. observations: - >- The spec's global `security` requirement references `new-auth`, while the only scheme actually DEFINED in securityDefinitions is `basic-auth`. That is a dangling reference in the provider's published Swagger 2.0 document — recorded as observed, not corrected. The narrative documentation is unambiguous that the mechanism is HTTP Basic. - No OAuth 2.0, OpenID Connect, mutual TLS, or scope surface is published, so scopes/ is deliberately absent for this provider rather than empty.