Skip to content
AuthOS AuthOS Documentation
StartGuidesDeployOperateReferencePackagesAI Skills
StartGuidesDeployOperateReferencePackagesAI Skills
  • Start Here
    • Evaluate AuthOS
    • Integrate a Frontend
    • Integrate a Backend
    • API Getting Started
    • SDK Getting Started
  • Guides
    • SDK Guides
    • Authentication Flows
      • OAuth Web Redirect
      • Admin Login
      • Device Authorization
      • Tokens and Sessions
      • Authentication Troubleshooting
    • Password Authentication
      • Registration
      • Email Verification
      • Login and Sessions
      • Password Reset
      • Account Management
      • Troubleshooting and Security
    • MFA Management
      • Enrollment
      • Verification
      • Backup and Recovery
      • Administration
      • UI Integration
      • Troubleshooting and Security
    • Passwordless Authentication
      • Passkeys
      • Magic Links
    • SCIM Provisioning
      • Concepts and Shared Setup
      • Okta
      • Microsoft Entra ID
      • OneLogin
      • Validation
      • Troubleshooting
    • Handle SDK Errors
    • Handle API Errors
      • Response Reference
      • Common Scenarios
      • Client Patterns
      • Testing and Debugging
      • Recovery Patterns
    • Compatibility and Versioning
  • Concepts
    • Architecture
    • Access Control
    • Authentication Flows
    • User and System Journeys
    • JWT Structure and Validation
    • Rate Limiting
    • Background Jobs
  • Deploy
    • Deployment Guide
  • Operate
    • Platform Overview
    • Organization Governance
    • Platform Users and MFA
    • Platform Audit Log
    • Platform Analytics
    • Platform Operations
    • User Impersonation
    • Health Checks
  • API Reference
    • Endpoints
      • Authentication
        • OAuth 2.0
        • Password Authentication
        • Multi-Factor Authentication
        • Magic Links
        • Passkeys
        • Device Authorization
        • Sessions
        • Hosted Auth Context
        • Home Realm Discovery
        • Enterprise-Managed Authorization
      • Users
      • Organizations
        • Organization CRUD
        • Members
        • Settings
        • OAuth Credentials
        • End Users
      • Services
        • Service Endpoints
        • Plans and Checkout
        • Billing Recipes
        • Security and Operations
        • Troubleshooting
      • Devices
      • Invitations
        • Endpoint Reference
        • Lifecycle and Security
        • Integration Recipes
        • Troubleshooting
      • API Keys
        • Endpoint Reference
        • Usage Recipes
        • Security and Operations
        • Troubleshooting
      • Service API
      • Organization Audit Logs
        • Endpoint Reference
        • Querying and Filtering
        • Export and Integrations
        • Compliance and Security
        • Troubleshooting
      • Enterprise
        • SIEM
        • SAML 2.0
          • Configuration
          • Certificate Rotation
          • Metadata and SSO
          • Single Logout
          • Integration Recipes
          • Security and Limitations
          • Troubleshooting
        • SCIM 2.0
      • Integrations
        • Webhooks
          • Configuration
          • Signing and Verification
          • Delivery and Retries
          • Event Catalog
          • Receiver Examples
          • Troubleshooting
        • Upstream Providers
      • Analytics
        • Endpoint Reference
        • Dashboard Recipes
        • Security and Operations
        • Troubleshooting
      • Privacy
      • Complete Endpoint Catalog
    • Appendix
      • Error Codes
      • Webhook Events
      • JWT Claims
      • OAuth Scopes
      • Changelog
  • SDK Reference
    • SDK Modules
      • Auth Module
        • Passkeys
        • Magic Links
      • User Module
      • Organizations Module
      • Permissions Module
      • Services Module
      • Analytics Module
      • Invitations Module
      • Platform Module
      • Service API Module
      • Privacy Module
  • Packages
    • React and Next.js
    • Vue and Nuxt
    • Node.js
    • AuthOS CLI
  • AI Skills
AuthOS is pre-1.0. Capabilities are Beta unless the project status says otherwise. These are latest-only docs with pre-1.0 pinning guidance. Review the readiness roadmap and security policy before deployment.
  1. Concepts

API Concepts

Core concepts and architectural patterns of the AuthOS API including JWT authentication, dual flows, and BYOO integration.

AuthOS release 0.8.5 API v1 Latest-only documentation

This section covers the core concepts and architectural patterns of the AuthOS API.

Pages

Architecture Overview

High-level overview of the AuthOS system architecture, core components, and data model.

Access Control

Understanding ReBAC permission system and authorization

Authentication Flows

Detailed guide to AuthOS provider-backed OAuth login, device authorization, passwordless, and session flows.

User and System Journeys

Concise route sequences for supported AuthOS authentication and administration flows.

JWT Structure & Validation

Comprehensive guide to AuthOS JSON Web Tokens, including structure, signing, and backend validation code examples.

Rate Limiting

Implemented AuthOS request limits, client-IP trust, email throttles, and safe retry behavior.

Background Jobs

Runtime workers for durable delivery, refresh, cleanup, and metrics.

Search AuthOS documentation

↑ ↓ select · Enter open · Esc close 0 results