alloy.com
Alloy provides identity risk decisioning and onboarding infrastructure for financial institutions and fintechs. Its platform supports entity creation, evaluations, event-driven monitoring, and case-related workflows.
Alloy exposes one documented HTTP API for onboarding, decisioning, entities, events, and related operations; it accepts either HTTP Basic auth with an Alloy-issued token/secret pair or an OAuth 2.0 client-credentials bearer token derived from that same pair.
- Alloy APIdiscovered
In the Alloy dashboard, go to Roles > Settings > API Keys and create a new API key. The docs say your role needs permissions to view API keys and create new API keys. Alloy issues a token and one or more secret values for that key; use them directly for HTTP Basic auth or as the client credentials for OAuth 2.0 client-credentials. See Account-Level API Keys and Authentication Guide.
First create an Alloy API token and secret from Account-Level API Keys. Then exchange them with the client-credentials flow by POSTing to https://sandbox.alloy.co/v1/oauth/bearer with grant_type=client_credentials and HTTP Basic auth using token:secret. The returned bearer token is valid for one hour and is then sent as Authorization: Bearer <bearer_token>. See Authentication Guide.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://alloy.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing