gravitee.io
Gravitee provides API management and access management software for publishing, securing, governing, and automating APIs and identity resources. Its products include APIM for managing API gateways and portals, and AM for identity, OAuth/OIDC, and security-domain management.
Gravitee exposes HTTP management APIs for API Management and Access Management, an Access Management automation API, and a Node-based APIM MCP server CLI; all documented surfaces require authentication.
- Gravitee APIM Management APIdiscovered
- Gravitee APIM Management API v2discovered
- Gravitee AM Automation APIdiscovered
- Gravitee AM Management APIdiscovered
- gravitee-apim-mcp-server CLIdiscovered
Use a Gravitee APIM management user account. In self-hosted installs this is created in the APIM console or identity provider configured for management access; the APIM Management API reference shows the API uses HTTP Basic auth and the APIM console lets admins create service accounts and personal tokens for delegated access. Start from the Management API Reference and your APIM console/admin setup for a user with the needed permissions.
Sign in to your APIM Console, go to Organization → Users, open your user or service account, then under Tokens click + Generate a personal token and copy the token. The APIM MCP documentation documents this flow for a service account. See Expose APIM as an MCP Server.
Use an Access Management administrator or management user account. The AM API reference shows you obtain a management API bearer token by calling /management/auth/token with HTTP Basic auth using your management username and password. See AM API Reference.
Call the AM token endpoint POST /management/auth/token with your AM management user credentials via HTTP Basic auth to receive an access_token, then use that bearer token in Authorization: Bearer .... See AM API Reference.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://gravitee.io/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing