API Reference

Complete endpoint documentation for the AuthOS API including authentication, user management, organizations, services, and integrations.

API Reference

Complete endpoint documentation for the AuthOS API.

Endpoints by Category

Authentication & Users

Organizations & Services

  • Organizations - Multi-tenant organization management, SMTP, domains, and branding
  • Services - Service configuration and OAuth settings
  • Invitations - Team member invitations and onboarding

Security & Access Control

  • API Keys - Service-to-service authentication
  • Service API - Backend API endpoints for services
  • SAML - SAML 2.0 Identity Provider

Governance & Integration

Operations & Monitoring

  • Health Checks - Service health, liveness, and readiness probes
  • Analytics - Login analytics and usage metrics

Pages

Authentication API

Comprehensive authentication endpoints including registration, login, OAuth flows, device authorization, JWT management, and session handling for both admins and end-users.

authentication oauth2 jwt device-flow registration

User Management API

Complete API documentation for user-related endpoints including profile management, password changes, MFA setup, backup codes, and OAuth identity linking.

user-management profile mfa password identities

Organization Management API

Comprehensive API for managing multi-tenant organizations including CRUD operations, member management, BYOO OAuth credentials, SMTP, custom domains, and branding.

organizations multi-tenant byoo members domains

Service Management API

Comprehensive API for managing services and subscription plans within organizations, including CRUD operations, plan management, and service limits enforcement.

services subscriptions plans limits

Invitations API

Team member invitation endpoints for onboarding users to organizations with role-based access control and expiration management.

invitations team-management onboarding roles

Subscription & Billing API

API for managing subscriptions and Stripe checkout sessions, enabling users to subscribe to paid plans.

subscriptions billing stripe checkout

API Key Management

Comprehensive API for managing API keys for service-to-service authentication, enabling secure backend access without user JWTs.

api-keys service-auth security backend

Service API

Secure service-to-service endpoints for managing users, subscriptions, and analytics using API key authentication for backend operations.

service-api api-keys backend subscriptions

SAML 2.0 Identity Provider API

SAML 2.0 IdP endpoints for enterprise integrations including configuration management, certificate handling, and SSO metadata.

saml identity-provider enterprise sso

Organization Audit Logs API

Comprehensive API for accessing organization audit logs with detailed tracking of administrative actions for compliance, security, and governance.

audit-logs compliance security governance

Audit Events Reference

Complete reference of all audit event types, triggering actions, and details payload schemas for organization and MFA audit logs.

audit-logs events compliance security

Webhooks API

Real-time event notification endpoints for subscribing to system events with automatic retries, signature verification, and delivery tracking.

webhooks events notifications integrations

Platform Owner API

Comprehensive administrative endpoints for managing AuthOS including governance, organization lifecycle, analytics, and security oversight.

platform admin governance super-admin

Analytics API

Endpoints for retrieving login and authentication analytics including user patterns, service usage monitoring, and OAuth provider adoption tracking.

analytics metrics reporting insights

Third-Party Integrations API

Integration endpoints for third-party services including Stripe billing, webhook handling, and external service connections.

integrations stripe billing third-party

SCIM 2.0 API

SCIM 2.0 provisioning API for automated user and group management

Health Check API

Operational health check endpoints for monitoring service availability, liveness probes, and database readiness checks.

health monitoring operations kubernetes

Privacy & GDPR API

GDPR compliance endpoints for data export and deletion (Right to Access and Right to be Forgotten)