Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

fly-io Tokens API

Operations for requesting OpenID Connect (OIDC) tokens from third-party services, enabling Fly Machines to authenticate to external systems using workload identity.

fly-io Tokens API is one of 9 APIs that fly-io publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Tokens. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 1 operation across 1 path, and defines 1 schema. It is described by OpenAPI 3.1.0, at version 1.0.

Requests are made against 2 base URLs: https://{provider_base_url}, https://api.fly.io.

1 operations 1 paths 1 schemas 1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
1.0
Base URL
https://api.machines.dev
Authentication
HTTP Bearer, HTTP Bearer, API Key
Terms of Service
Resource Areas
1

Authentication & Security 3

fly-io Tokens API declares 3 security schemes for authenticating requests. It accepts HTTP bearer tokens (flySharedSecret). It accepts HTTP bearer tokens (oauthBearerAuth). An API key is passed in the header as X-Fly-Signature (webhookHmac). By default, every request must be authenticated.

  • flySharedSecret — Shared secret provided by Fly.io to the extension provider. Fly.io includes this secret in an Authorization Bearer header on all requests to the provider's API…
  • oauthBearerAuth — Fly.io OAuth access token obtained from the token exchange endpoint.
  • webhookHmac — HMAC-SHA256 signature of the raw request body, computed using the webhook signing secret. Recipients must verify this signature before processing the payload.

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.

Tokens 1

Operations for requesting OpenID Connect (OIDC) tokens from third-party services, enabling Fly Machines to authenticate to external systems using workload identity.

POST
/v1/tokens/oidc
Get an OIDC token
getOidcToken body → 200401

Schemas 1

The contract defines 1 schema that model the data the API accepts and returns. The most detailed is ErrorResponse (2 properties). Each schema is shown below with its type and property counts.

ErrorResponse
object
A standard error response returned by the API on failure.
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

fly-io-tokens-api-openapi.yml Raw ↑

Other APIs fly-io publishes across the network.

Fly.io Machines API
Fly.io GraphQL API
Fly.io Extensions API
fly-io Apps API
fly-io OAuth API
fly-io SSO API
fly-io Volumes API
fly-io Webhooks API