HTTP API Reference
API documentation organized by app. Select an app to view its endpoints, permissions, and examples.
X-API-Key or Authorization: Bearer with a valid organization API key. Each endpoint checks the permission scopes granted to the key. The admin permission grants full access.Governance & Management
Admin Portal
Self-serve IT admin portal for SSO, SCIM, and domains.
Users
Directory users for this sub-organization — add without invites.
Sessions
Active sessions with device metadata — list and revoke access.
RBAC
Roles, permissions, and Staging/Production environments.
SCIM
Automated user and group sync from your identity provider.
Authentication
Auth
Core end-user authentication — session policy, login/signup APIs, and method orchestration.
Email and Password
Email and password sign-in — password policy, lockout, and sign-up rules. Enable the app in Apps; configure policy on the dashboard.
Enterprise SSO
SAML and OIDC single sign-on for enterprise customers.
MFA
TOTP, backup codes, and enforcement policies for step-up auth.
Passkeys
Passwordless WebAuthn sign-in with device biometrics.
OTP
WordAuth word-pair and digital numeric OTP — formats, delivery, and rate limits.
Social Login
OAuth sign-in with Google, Apple, Microsoft, and GitHub.
Magic Link
Passwordless email magic links — TTL, rate limits, and delivery. Enable the app in Apps; configure limits on the dashboard.
Phish Auth
User safety tool to verify suspicious contact before acting.