generated: '2026-08-13' method: searched source: >- https://api.revenue.io/.well-known/oauth-authorization-server (probed) and https://support.revenue.io/guided-selling/salesforce-administration/installation-and-setup/setup-api-credentials/ docs: >- https://support.revenue.io/guided-selling/salesforce-administration/installation-and-setup/setup-api-credentials/ note: >- DERIVED FROM DOCS AND LIVE PROBES, NOT FROM AN OPENAPI — Revenue.io publishes no machine-readable API contract, so there are no securitySchemes to aggregate. Two distinct authentication surfaces exist and they are not the same product. summary: types: [oauth2, apiKey] api_key_in: [application-configuration] oauth2_flows: [authorizationCode] self_service: false schemes: - name: mcp-oauth2 type: oauth2 surface: https://app.ringdna.com/mcp description: >- OAuth 2.1 authorization-code flow with PKCE protecting Revenue.io's remote MCP server. Dynamic client registration (RFC 7591) is advertised, so an MCP client can register itself; token endpoint auth method is "none" (public client). Confirmed live: an unauthenticated tools/list POST returns 401 with a WWW-Authenticate Bearer challenge. flows: - flow: authorizationCode authorizationUrl: https://app.ringdna.com/mcp/oauth/authorize tokenUrl: https://app.ringdna.com/mcp/oauth/token registrationUrl: https://app.ringdna.com/mcp/oauth/register pkce: S256 scopes: mcp: the single scope advertised in scopes_supported token_endpoint_auth_methods_supported: [none] bearer_methods_supported: [header] sources: - well-known/revenue-io-oauth-authorization-server.json - well-known/revenue-io-oauth-protected-resource.json - name: guided-selling-api-credentials type: apiKey surface: Guided Selling managed package -> Settings -> Setup description: >- An API Key and API Secret pair that lets a customer's Guided Selling instance in Salesforce talk to Revenue.io servers — required for sending emails, executing template actions and permission checks. The credentials are bound to the customer's Salesforce Organization ID. issuance: >- NOT SELF-SERVICE. Revenue.io states the credentials "are generated by your Implementation Manager or the Support Team" — there is no developer console, no key-generation UI and no public signup that yields a key. rotation: >- Credentials are tied to the Salesforce Organization ID; a partial-copy sandbox refresh can change that Org ID, and the customer must contact Revenue.io Support to have the new Org ID re-bound. sources: - >- https://support.revenue.io/guided-selling/salesforce-administration/installation-and-setup/setup-api-credentials/ - name: salesforce-oauth type: oauth2 surface: RingDNA Communications Hub sign-in description: >- End users authenticate into the RingDNA dialer via Salesforce OAuth / Salesforce SSO. Documented only through troubleshooting articles (OAuth access scope, IP-restricted OAuth failures); Revenue.io publishes no authorization/token endpoints of its own for this path — Salesforce is the identity provider. sources: - https://support.revenue.io/integrations/salesforce/common-salesforce-errors/oauth-access-scope/ - https://support.revenue.io/ringdna/troubleshooting/signing-in/salesforce-oauth-failed-ip-restricted/ network_controls: ip_allowlist: https://support.revenue.io/administration/managing-salesforce-configurations-and-settings/ip-whitelist-security/