How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Flagsmith Authentication API

Authentication, MFA, OAuth, and token management.

Flagsmith Authentication API is one of 24 APIs that Flagsmith publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Authentication. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 59 operations across 40 paths, and defines 43 schemas. It is described by OpenAPI 3.2.0, at version v1.

Requests are made against the base URL https://edge.api.flagsmith.com.

59 operations 40 paths 43 schemas 7 DELETE12 GET6 PATCH29 POST5 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1
Base URL
https://edge.api.flagsmith.com
Authentication
HTTP Bearer, HTTP Basic, API Key, API Key, HTTP Basic, API Key
License
BSD License
Resource Areas
1

Authentication & Security 6

Flagsmith Authentication API declares 6 security schemes for authenticating requests. It accepts HTTP bearer tokens (Cohort_Sync_Key). It accepts HTTP basic authentication (Cohort_Sync_Key__Basic). An API key is passed in the header as X-Environment-Key (Environment_API_Key). An API key is passed in the header as Authorization (Master_API_Key). It accepts HTTP basic authentication (basicAuth). An API key is passed in the header as Authorization (tokenAuth).

  • Cohort_Sync_Key — For cohort sync endpoints called by an external cohort source, such as Amplitude.
  • Cohort_Sync_Key__Basic — For cohort sync endpoints called by an external cohort source that can only send Basic credentials, such as Mixpanel. The key is the password; the username is…
  • Environment_API_Key — For SDK endpoints. Find out more .
  • Master_API_Key — For Management API endpoints. Find out more .
  • tokenAuth — Token-based authentication with required prefix "Token"

Paths & Operations 59

Across 40 paths, the API surfaces 59 operations — 7 DELETE, 12 GET, 6 PATCH, 29 POST, 5 PUT. Each is listed below with its method, path, parameters, and response codes.

Authentication 59

Authentication, MFA, OAuth, and token management.

POST
/api/v1/auth/{method}/activate/
Api v1 auth activate create
api_v1_auth_activate_create 1 param → 200
POST
/api/v1/auth/{method}/activate/confirm/
Api v1 auth activate confirm create
api_v1_auth_activate_confirm_create 1 param → 200
POST
/api/v1/auth/{method}/deactivate/
Api v1 auth deactivate create
api_v1_auth_deactivate_create 1 param → 200
POST
/api/v1/auth/login/
Api v1 auth login create
api_v1_auth_login_create body → 200
POST
/api/v1/auth/login/code/
Api v1 auth login code create
api_v1_auth_login_code_create body → 200
POST
/api/v1/auth/logout/
Api v1 auth logout create
api_v1_auth_logout_create → 204
GET
/api/v1/auth/mfa/user-active-methods/
Api v1 auth mfa user active methods retrieve
api_v1_auth_mfa_user_active_methods_retrieve → 200
POST
/api/v1/auth/oauth/github/
Api v1 auth oauth github create
api_v1_auth_oauth_github_create body → 200502
POST
/api/v1/auth/oauth/google/
Api v1 auth oauth google create
api_v1_auth_oauth_google_create body → 200502
POST
/api/v1/auth/oidc/token/
Oidc token exchange
oidc_token_exchange body → 200400401
POST
/api/v1/auth/saml/{name}/request/
Api v1 auth saml request create
api_v1_auth_saml_request_create 2 params → 200
POST
/api/v1/auth/saml/{name}/response/
Api v1 auth saml response create
api_v1_auth_saml_response_create 2 params → 200
GET
/api/v1/auth/saml/attribute-mapping/
Api v1 auth saml attribute mapping list
api_v1_auth_saml_attribute_mapping_list 3 params → 200
POST
/api/v1/auth/saml/attribute-mapping/
Api v1 auth saml attribute mapping create
api_v1_auth_saml_attribute_mapping_create body → 201
GET
/api/v1/auth/saml/attribute-mapping/{id}/
Api v1 auth saml attribute mapping retrieve
api_v1_auth_saml_attribute_mapping_retrieve 1 param → 200
PUT
/api/v1/auth/saml/attribute-mapping/{id}/
Api v1 auth saml attribute mapping update
api_v1_auth_saml_attribute_mapping_update 1 param body → 200
PATCH
/api/v1/auth/saml/attribute-mapping/{id}/
Api v1 auth saml attribute mapping partial update
api_v1_auth_saml_attribute_mapping_partial_update 1 param body → 200
DELETE
/api/v1/auth/saml/attribute-mapping/{id}/
Api v1 auth saml attribute mapping destroy
api_v1_auth_saml_attribute_mapping_destroy 1 param → 204
GET
/api/v1/auth/saml/configuration/
Api v1 auth saml configuration list
api_v1_auth_saml_configuration_list 2 params → 200
POST
/api/v1/auth/saml/configuration/
Api v1 auth saml configuration create
api_v1_auth_saml_configuration_create body → 201
GET
/api/v1/auth/saml/configuration/{name}/
Api v1 auth saml configuration retrieve
api_v1_auth_saml_configuration_retrieve 1 param → 200
PUT
/api/v1/auth/saml/configuration/{name}/
Api v1 auth saml configuration update
api_v1_auth_saml_configuration_update 1 param body → 200
PATCH
/api/v1/auth/saml/configuration/{name}/
Api v1 auth saml configuration partial update
api_v1_auth_saml_configuration_partial_update 1 param body → 200
DELETE
/api/v1/auth/saml/configuration/{name}/
Api v1 auth saml configuration destroy
api_v1_auth_saml_configuration_destroy 1 param → 204
POST
/api/v1/auth/saml/login/
Api v1 auth saml login create
api_v1_auth_saml_login_create body → 200401
DELETE
/api/v1/auth/token/
Api v1 auth token destroy
api_v1_auth_token_destroy → 204
GET
/api/v1/auth/users/
Api v1 auth users list
api_v1_auth_users_list 1 param → 200
POST
/api/v1/auth/users/
Api v1 auth users create
api_v1_auth_users_create body → 201
GET
/api/v1/auth/users/{id}/
Api v1 auth users retrieve
api_v1_auth_users_retrieve 1 param → 200
PUT
/api/v1/auth/users/{id}/
Api v1 auth users update
api_v1_auth_users_update 1 param body → 200
PATCH
/api/v1/auth/users/{id}/
Api v1 auth users partial update
api_v1_auth_users_partial_update 1 param body → 200
DELETE
/api/v1/auth/users/{id}/
Api v1 auth users destroy
api_v1_auth_users_destroy 3 params → 204
POST
/api/v1/auth/users/activation/
Api v1 auth users activation create
api_v1_auth_users_activation_create body → 200
GET
/api/v1/auth/users/me/
Api v1 auth users me retrieve
api_v1_auth_users_me_retrieve → 200
PUT
/api/v1/auth/users/me/
Api v1 auth users me update
api_v1_auth_users_me_update body → 200
PATCH
/api/v1/auth/users/me/
Api v1 auth users me partial update
api_v1_auth_users_me_partial_update body → 200
DELETE
/api/v1/auth/users/me/
Api v1 auth users me destroy
api_v1_auth_users_me_destroy → 204
PATCH
/api/v1/auth/users/me/onboarding/
Api v1 auth users me onboarding partial update
api_v1_auth_users_me_onboarding_partial_update body → 200
POST
/api/v1/auth/users/resend_activation/
Api v1 auth users resend activation create
api_v1_auth_users_resend_activation_create body → 200
POST
/api/v1/auth/users/reset_email/
Api v1 auth users reset email create
api_v1_auth_users_reset_email_create body → 200
POST
/api/v1/auth/users/reset_email_confirm/
Api v1 auth users reset email confirm create
api_v1_auth_users_reset_email_confirm_create body → 200
POST
/api/v1/auth/users/reset_password/
Api v1 auth users reset password create
api_v1_auth_users_reset_password_create body → 200
POST
/api/v1/auth/users/reset_password_confirm/
Api v1 auth users reset password confirm create
api_v1_auth_users_reset_password_confirm_create body → 200
POST
/api/v1/auth/users/set_email/
Api v1 auth users set email create
api_v1_auth_users_set_email_create body → 200
POST
/api/v1/auth/users/set_password/
Api v1 auth users set password create
api_v1_auth_users_set_password_create body → 200
POST
/api/v1/organisations/{organisation_pk}/groups/{group_pk}/users/{user_pk}/make-admin
Api v1 organisations groups users make admin create
api_v1_organisations_groups_users_make_admin_create 3 params → 200
POST
/api/v1/organisations/{organisation_pk}/groups/{group_pk}/users/{user_pk}/remove-admin
Api v1 organisations groups users remove admin create
api_v1_organisations_groups_users_remove_admin_create 3 params → 200
GET
/api/v1/organisations/{organisation_pk}/roles/{role_pk}/users/
Api v1 organisations roles users list
api_v1_organisations_roles_users_list 3 params → 200
POST
/api/v1/organisations/{organisation_pk}/roles/{role_pk}/users/
Api v1 organisations roles users create
api_v1_organisations_roles_users_create 2 params body → 201
GET
/api/v1/organisations/{organisation_pk}/roles/{role_pk}/users/{id}/
Api v1 organisations roles users retrieve
api_v1_organisations_roles_users_retrieve 3 params → 200
PUT
/api/v1/organisations/{organisation_pk}/roles/{role_pk}/users/{id}/
Api v1 organisations roles users update
api_v1_organisations_roles_users_update 3 params body → 200
PATCH
/api/v1/organisations/{organisation_pk}/roles/{role_pk}/users/{id}/
Api v1 organisations roles users partial update
api_v1_organisations_roles_users_partial_update 3 params body → 200
DELETE
/api/v1/organisations/{organisation_pk}/roles/{role_pk}/users/{id}/
Api v1 organisations roles users destroy
api_v1_organisations_roles_users_destroy 3 params → 204
GET
/api/v1/organisations/{organisation_pk}/users/
Api v1 organisations users list
api_v1_organisations_users_list 1 param → 200
POST
/api/v1/organisations/{organisation_pk}/users/{id}/update-role/
Api v1 organisations users update role create
api_v1_organisations_users_update_role_create 2 params body → 200
GET
/api/v1/organisations/{organisation_pk}/users/{user_pk}/roles/
Api v1 organisations users roles list
api_v1_organisations_users_roles_list 3 params → 200
DELETE
/api/v1/organisations/{organisation_pk}/users/{user_pk}/roles/{id}/
Api v1 organisations users roles destroy
api_v1_organisations_users_roles_destroy 3 params → 204
POST
/api/v1/users/join/{hash}/
Api v1 users join create
api_v1_users_join_create 1 param → 200
POST
/api/v1/users/join/link/{hash}/
Api v1 users join link create
api_v1_users_join_link_create 1 param → 200

Schemas 43

The contract defines 43 schemas that model the data the API accepts and returns. The most detailed are SamlCurrentUser (10 properties), CustomUserCreate (10 properties), PatchedSamlCurrentUser (10 properties), SamlConfiguration (6 properties). Each schema is shown below with its type and property counts.

User
object
5 properties 2 required
SetUsername
object
2 properties 2 required
SignUpTypeEnum
string
NOINVITE - No Invite INVITEEMAIL - Invite Email INVITELINK - Invite Link
SamlCurrentUser
object
10 properties 2 required
SamlRequest
object
3 properties 3 required
OAuthToken
object
2 properties
SamlLogin
object
1 property 1 required
PatchedSamlCurrentUser
object
10 properties
UserRole
object
3 properties 1 required
SetPasswordRetype
object
3 properties 3 required
Activation
object
2 properties 2 required
PatchedSamlConfiguration
object
6 properties
PaginatedRoleList
object
4 properties 2 required
Role
object
5 properties 1 required
PatchedUser
object
5 properties
PaginatedSamlConfigurationList
object
4 properties 2 required
Error
object
1 property 1 required
PaginatedSamlAttributeMappingList
object
4 properties 2 required
TokenCreate
object
2 properties
UTMData
object
5 properties
SamlUserToken
object
1 property 1 required
PaginatedUserList
object
4 properties 2 required
UsernameResetConfirm
object
1 property 1 required
TokenExchangeRequest
object
1 property 1 required
TokenExchangeResponse
object
3 properties 3 required
CustomUserCreate
object
10 properties 4 required
SamlConfiguration
object
6 properties 3 required
PatchedUserRole
object
3 properties
PatchedSamlAttributeMapping
object
4 properties
SamlAttributeMapping
object
4 properties 3 required
SamlRequestHeaders
object
1 property 1 required
NullEnum
null
UserOrganisation
object
3 properties 1 required
BlankEnum
RoleEnum
string
ADMIN - Admin USER - User
DjangoAttributeNameEnum
string
email - Email firstname - First / Given name lastname - Last name / Surname groups - Groups
GithubLogin
object
5 properties 1 required
SendEmailReset
object
1 property 1 required
GoogleLogin
object
5 properties 1 required
UserList
object
6 properties 3 required
OrganisationSerializerBasic
object
2 properties 1 required
PaginatedUserRoleList
object
4 properties 2 required
PasswordResetConfirmRetype
object
4 properties 4 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

flagsmith-authentication-api-openapi.yml Raw ↑

Other APIs Flagsmith publishes across the network.

Flagsmith Flags API
flagsmith Environments API
flagsmith Features API
flagsmith Identities API
flagsmith Organisations API
flagsmith Projects API
flagsmith Segments API
flagsmith Users API
flagsmith Webhooks API
Flagsmith Admin dashboard API
Flagsmith Analytics API
Flagsmith Audit API
Where this information came from

This is an independent, third-party profile of Flagsmith Authentication API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.