Apidog Docs
πŸ‡ΊπŸ‡Έ English
  • πŸ‡ΊπŸ‡Έ English
  • πŸ‡―πŸ‡΅ ζ—₯本θͺž
HomeLearning Center
Support CenterAPI ReferencesDownloadChangelog
HomeLearning Center
Support CenterAPI ReferencesDownloadChangelog
Discord Community
Slack Community
X / Twitter
πŸ‡ΊπŸ‡Έ English
  • πŸ‡ΊπŸ‡Έ English
  • πŸ‡―πŸ‡΅ ζ—₯本θͺž
πŸ‡ΊπŸ‡Έ English
  • πŸ‡ΊπŸ‡Έ English
  • πŸ‡―πŸ‡΅ ζ—₯本θͺž
  1. Authentication and Authorization
  • Apidog Learning Center
  • Getting Started
    • Introduction to Apidog
    • Basic Concepts in Apidog
    • Navigating Apidog
    • Quick Start
      • Overview
      • Creating an Endpoint
      • Making a Request
      • Adding an Assertion
      • Creating Test Scenarios
      • Sharing API Documentation
      • Explore More
    • Migration to Apidog
      • Overview
      • Manual Import
      • Scheduled Import (Bind Data Sources)
      • Import Options
      • Export Data
      • Import From
        • Import from Postman
        • Import OpenAPI Spec
        • Import cURL
        • Import Markdowns
        • Import from Insomnia
        • Import from apiDoc
        • Import .har File
        • Import WSDL
  • Design APIs
    • Overview
    • Create a New API Project
    • Endpoint Basics
    • APl Design Guidelines
    • Module
    • Configure Multiple Request Body Examples
    • Components
    • Common Fields
    • Global Parameters
    • Endpoint Change History
    • Comments
    • Batch Endpoint Management
    • Custom Protocol API
    • Schemas
      • Overview
      • Create a New Schema
      • Build a Schema
      • Generate Schemas from JSON Etc
      • oneOf, allOf, anyOf
      • Using Discriminator
    • Security Schemes
      • Overview
      • Create a Security Scheme
      • Use the Security Scheme
      • Security Scheme in Online Documentation
    • Advanced Features
      • Custom Endpoint Fields
      • Associated Test Scenarios
      • Endpoint Status
      • Appearance of Parameter Lists
      • Endpoint Unique Identification
  • Develop and Debug APIs
    • Overview
    • Generating Requests
    • Sending Requests
    • Debugging Cases
    • Test Cases
    • Dynamic Values
    • Validating Responses
    • Design-First vs Request-First
    • Generating Code
    • Environments & Variables
      • Overview
      • Environment Management
      • Using Variables
    • Vault Secrets
      • Overview
      • HashiCorp Vault
      • Azure Key Vault
      • AWS Secrets Manager
    • Pre and Post Processors
      • Assertion
      • Extract Variable
      • Wait
      • Overview
      • Using Scripts
        • Overview
        • Pre Processor Scripts
        • Post Processor Scripts
        • Public Scripts
        • Postman Scripts Reference
        • Calling Other Programming Languages
        • Using JS Libraries
        • Visualizing Responses
        • Script Examples
          • Assertion Scripts
          • Using Variables
          • Modifying Requests
          • Other Examples
      • Database Operations
        • Overview
        • MySQL
        • MongoDB
        • Redis
        • Oracle Client
    • Dynamic Values Modules
  • Mock API Data
    • Overview
    • Smart Mock
    • Custom Mock
    • Mock Priority Sequence
    • Mock Scripts
    • Cloud Mock
    • Self-Hosted Runner Mock
    • Mock Language (Locales)
  • API Testing
    • Overview
    • Test Scenarios
      • Create a Test Scenario
      • Pass Data Between Requests
      • Flow Control Conditions
      • Sync Data from Endpoints and Endpoint Cases
      • Import Endpoints and Endpoint Cases from Other Projects
      • Export Test Scenarios
    • Run Test Scenarios
      • Run a Test Scenario
      • Run Test Scenarios in Batch
      • Manage Runtime Environment of APIs from Other Projects
      • Data-Driven Testing
      • Scheduled Tasks
    • Test Suite
      • Overview
      • Create A Test Suite
      • Orchestrate Test Suite
      • Run Test Suites Locally
      • Run Test Suites Via CLI
      • Scheduled tasks
    • Test Reports
      • Test Reports
    • Test APIs
      • Integration Testing
      • Performance Testing
      • End-to-End Testing
      • Regression Testing
      • Contract Testing
    • Apidog CLI
      • Overview
      • Installing and Running Apidog CLI
      • Apidog CLI Options
    • CI CD
      • Overview
      • Integrate with Gitlab
      • Integrate with Jenkins
      • Trigger Test by Git Commit
      • Integrate with Github Actions
  • Publish API Docs
    • Overview
    • API Technologies Supported
    • Quick Share
    • Viewing API Documentation
    • Markdown Documentation
    • Publishing Documentation Sites
    • Custom Layouts
    • Custom CSS, JavaScript, HTML
    • Custom Domain
    • LLM-Friendly Features
    • SEO Settings
    • Advanced Settings
      • Documentation Search
      • CORS Proxy
      • Integrating Google Analytics with Doc Sites
      • Folder Tree Settings
      • Visibility Settings
      • Embedding Values in Document URLs
    • API Versions
      • Overview
      • Creating API Versions
      • Publishing API Versions
      • Sharing Endpoints with API Versions
  • Send Requests
    • Overview
    • SSE Debugging
    • MCP Client
    • Socket.IO
    • WebSocket
    • Webhook
    • SOAP or WebService
    • GraphQL
    • gRPC
    • Use Request Proxy Agents for Debugging
    • Create Requests
      • Request History
      • Request Basics
      • Parameters and Body
      • Request Headers
      • Request Settings
      • Debug Requests
      • Saving Requests as Endpoints
      • HTTP/2
    • Response and Cookies
      • Viewing API Responses
      • Managing Cookies
      • Overview
    • Authentication and Authorization
      • Overview
      • CA and Client Certificates
      • Authorization Types
      • Digest Auth
      • OAuth 1.0
      • OAuth 2.0
      • Hawk Authentication
      • Kerberos
      • NTLM
      • Akamai EdgeGrid
  • Branches
    • Overview
    • Create a new sprint branch
    • Test APIs in a branch
    • Design API in a branch
    • Merge sprint branches
    • Manage sprint branches
  • AI Features
    • Overview
    • Enable AI features
    • Generate Test Cases
    • Modify schemas with AI
    • Endpoint compliance check
    • API documentation completeness check
    • AI naming
    • FAQs
  • Apidog MCP Server
    • Overview
    • Connect API Specification within Apidog Project to AI via Apidog MCP Server
    • Connect Online API Documentation Published by Apidog to AI via Apidog MCP Server
    • Connect OpenAPI Files to AI via Apidog MCP Server
  • Best Practices
    • How to handle API signatures
    • How to access OAuth 2.0 protected APIs
    • Apidog collaboration workflow
    • Managing authentication state in Apidog
  • Offline Space
    • Overview
  • Administration
    • Onboarding Checklist
      • Basic Concepts
      • Onboarding Guide
    • Managing teams
      • Managing Teams
      • Managing Team Members
      • Member Roles & Permission Settings
      • Team Activities
      • Team Resources
        • General Runner
        • Team Variables
        • Request Proxy Agent
      • Real-time Collaborations
        • Team Collaboration
    • Managing Projects
      • Managing Projects
      • Managing Project Members
      • Notification Settings
      • Project Resources
        • Database Connection
        • Git Connection
    • Managing Organization
      • Managing Organization
      • Single Sign-On (SSO)
        • SSO Overview
        • Configure Microsoft Entra ID
        • Configure Okta
        • Configure SSO for an Organization
        • Managing user accounts
        • Mapping Groups to Teams
      • SCIM Provisioning
        • Intro to SCIM Provisioning
        • Microsoft Entra ID
        • Okta
      • Organization Resources
        • Self-hosted Runner
      • Plans management
        • Billing managers in organization
  • Billing
    • Overview
    • Credits
    • Unable to use credit cards
    • Managing subscriptions
    • Upgrade plan
    • How to move a paid team to a organization
  • Data & Security
    • Apidog data storage location and security
    • User data privacy and storage location
    • Request routing and data security
  • Add-ons
    • API Hub
    • Apidog Intellij IDEA plugin
    • Browser Extension
      • Chrome
      • Microsoft Edge
    • Request Proxy
      • Request proxy in Apidog web
      • Request proxy in shared docs
      • Request proxy in Apidog client
  • Account & preferences
    • Account settings
    • Generate OpenAPI access token
    • Notification
    • Language settings
    • Hot keys
    • Network proxy configuration
    • Data backup
    • Updating Apidog
    • Deleting account
    • Experimental Features
  • References
    • API-Design First Approach
    • Apidog OpenAPI Specificaiton Extensions
    • JSONPath
    • XPath
    • Regular Expressions
    • JSON Schema
    • CSV File Format
    • Install Java Environment
    • Runner deployment environment
    • Apidog flavored Markdown
  • Apidog Europe
    • Apidog Europe
  • Support Center
HomeLearning Center
Support CenterAPI ReferencesDownloadChangelog
HomeLearning Center
Support CenterAPI ReferencesDownloadChangelog
Discord Community
Slack Community
X / Twitter
πŸ‡ΊπŸ‡Έ English
  • πŸ‡ΊπŸ‡Έ English
  • πŸ‡―πŸ‡΅ ζ—₯本θͺž
πŸ‡ΊπŸ‡Έ English
  • πŸ‡ΊπŸ‡Έ English
  • πŸ‡―πŸ‡΅ ζ—₯本θͺž
  1. Authentication and Authorization

Authorization Types

Apidog offers various authentication methods for API requests, enabling you to secure your integrations and access protected resources. This page provides a comprehensive reference of all supported authorization types and how to configure them in Apidog.
You can select an authentication type from the Type menu in the Authorization section of a request. Authentication can be applied at the request, folder, or collection level, providing flexibility in how you manage credentials across your API workspace.

Authorization Types Comparison#

TypeUse CaseSecurity LevelCommon Applications
Inherit from ParentReuse auth from parent folder/collectionVariesOrganizing requests with shared auth
No AuthPublic endpointsNoneHealth checks, public data
API KeySimple token-based authMediumInternal APIs, basic integrations
Bearer TokenToken-based auth (JWT, etc.)Medium-HighModern APIs, microservices
JWT BearerSelf-generated JWT tokensHighCustom JWT implementations
Basic AuthUsername/passwordLow-MediumLegacy systems, simple auth
Digest AuthEncrypted username/passwordMediumEnhanced security over Basic Auth
OAuth 1.0Delegated authorization (legacy)MediumTwitter API, legacy services
OAuth 2.0Modern delegated authorizationHighGoogle, GitHub, Microsoft APIs
Hawk AuthenticationHMAC-based authHighSpecialized secure APIs
NTLMWindows authenticationMediumMicrosoft environments
Akamai EdgeGridAkamai CDN authenticationHighAkamai services

Inherit from Parent#

Simplify Auth Management
"Inherit from Parent" is the default auth type in Apidog. When a request's auth type is set to "Inherit from Parent," it will inherit the auth configuration from its parent folder, and continue inheriting up to the root folder. This allows you to configure auth once at the folder level and apply it to all child requests automatically.
Benefits:
Centralized auth management
Easier credential updates
Consistent auth across related requests

No Auth#

If no authentication is required, Apidog won't include any authorization details. Simply choose No Auth from the Type dropdown in the Authorization tab for unauthenticated requests.
When to use:
Public API endpoints
Health check endpoints
Endpoints that handle auth in custom ways

API Key#

For API key auth, you provide a key-value pair in either the request headers or query parameters. Select API Key from the Type options, enter your key name and value, and choose to add it to either Headers or Query Params.
Apidog will automatically append the necessary information to your request Headers or URL query string.
Security Best Practice
For enhanced security, store API keys in environment variables instead of hardcoding them in requests. This prevents accidental exposure in version control or shared workspaces.

Bearer Token#

Bearer token auth, such as JSON Web Tokens (JWT), uses an access key in the request header. Choose Bearer Token from the Type list and input your API key in the Token field.
Apidog will add the token to the Authorization header in this format:
Bearer <Your API key>
Custom Prefixes
For custom prefixes other than "Bearer", use the API Key option with "Authorization" as the key name.

JWT Bearer#

Apidog also supports JWT token generation directly within the application. Select JWT Bearer from the Type options.
Configuration options:
Location: Add token to Request Header or Query Param
Algorithm: Choose from HS, RS, ES, or PS variants with SHA
Secret/Key: Enter the necessary secret or private key
Payload: Input payload data in JSON format
Advanced settings allow you to configure header prefixes and custom headers.

Basic Auth#

Basic auth involves sending verified credentials with your request. Select Basic Auth from the Type menu and enter your API username and password.
Apidog will include an Authorization header with a Base64 encoded string of your credentials in this format:
Basic <Base64 encoded username and password>
Security Limitation
Basic Auth transmits credentials in Base64 encoding, which is easily decoded. Always use HTTPS when using Basic Auth, and consider more secure alternatives like OAuth 2.0 for production environments.

Other Authorization Types#

Apidog also supports these advanced authorization methods:
Digest Auth - Enhanced security over Basic Auth with encryption
OAuth 1.0 - Legacy delegated authorization protocol
OAuth 2.0 - Modern delegated authorization with multiple grant types
Hawk Authentication - HMAC-based authentication protocol
NTLM - Windows NT LAN Manager authentication
Akamai EdgeGrid - Akamai CDN authentication protocol
For detailed configuration instructions for each type, click the links above to view the dedicated documentation pages.
Modified atΒ 2026-01-22 10:53:56
Previous
CA and Client Certificates
Next
Digest Auth
Built with