How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

AGNTCY Auth Service API

AuthService manages auth.

AGNTCY Auth Service API is one of 21 APIs that AGNTCY publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 2 JSON Schema definitions.

Tagged areas include AuthService. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, and 2 JSON Schemas.

This API exposes 5 operations across 5 paths, and defines 10 schemas. It is described by OpenAPI 3.2.0, at version v1alpha1.

Requests are made against a single base URL, http://localhost:4000.

5 operations 5 paths 10 schemas 1 GET4 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1alpha1
Base URL
https://schema.oasf.outshift.com/api
Authentication
HTTP Bearer, API Key
Resource Areas
1

Authentication & Security 2

AGNTCY Auth Service API declares 2 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (AccessToken). An API key is passed in the header as x-id-api-key (ApiKey). By default, every request must be authenticated.

  • AccessToken — An IAM JWT token issued to a user during an OIDC flow.
  • ApiKey — An IAM Api key.

Paths & Operations 5

Across 5 paths, the API surfaces 5 operations — 1 GET, 4 POST. Each is listed below with its method, path, parameters, and response codes.

AuthService 5

AuthService manages auth.

GET
/v1alpha1/auth/app_info
App info endpoint
AuthService_AppInfo → 200default
POST
/v1alpha1/auth/approve_token
Handle manual approval of external authorization requets
AuthService_ApproveToken body → 200default
POST
/v1alpha1/auth/authorize
Authorize a request from an Agent or MCP Server
AuthService_Authorize body → 200default
POST
/v1alpha1/auth/ext_authz
Handle external authorization requests
AuthService_ExtAuthz body → 200default
POST
/v1alpha1/auth/token
Request token for an Agent or MCP Server
AuthService_Token body → 200default

Schemas 10

The contract defines 10 schemas that model the data the API accepts and returns. The most detailed are App (8 properties), ApproveTokenRequest (4 properties), AuthorizeRequest (3 properties), Status (3 properties). Each schema is shown below with its type and property counts.

ApproveTokenRequest
object
4 properties
ExtAuthzRequest
object
2 properties
TokenResponse
object
1 property
GoogleProtobufAny
object
Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
1 property
AppInfoResponse
object
1 property
Status
object
The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by [gRPC](h…
3 properties
TokenRequest
object
1 property
AuthorizeRequest
object
3 properties
AuthorizeResponse
object
1 property
App
object
Identity Service App.
8 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

agntcy-authservice-api-openapi.yml Raw ↑

Other APIs AGNTCY publishes across the network.

Agent Directory (DIR)
AGNTCY Agents API
AGNTCY App Service API
AGNTCY Badge Service API
AGNTCY Classes and Objects API
AGNTCY Device Service API
AGNTCY ID Service API
AGNTCY Issuer Service API
AGNTCY JSON Schema API
AGNTCY Policy Service API
AGNTCY Sample Data API
AGNTCY Schema API
Where this information came from

This is an independent, third-party profile of AGNTCY Auth Service API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.