Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Hex.pm OAuth API

OAuth2 Device Authorization Grant flow.

Hex.pm OAuth API is one of 12 APIs that Hex.pm publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include OAuth. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and rate-limit docs.

This API exposes 4 operations across 4 paths, and defines 5 schemas. It is described by OpenAPI 3.0.3, at version 1.0.0.

Requests are made against a single base URL, https://hex.pm/api.

4 operations 4 paths 5 schemas 4 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.3
API Version
1.0.0
Base URL
https://hex.pm/api
Authentication
API Key, HTTP Bearer, HTTP Basic
Terms of Service
Resource Areas
1

Authentication & Security 3

Hex.pm OAuth API declares 3 security schemes for authenticating requests. An API key is passed in the header as Authorization (ApiKeyAuth). It accepts HTTP bearer tokens (BearerAuth). It accepts HTTP basic authentication (BasicAuth). By default, every request must be authenticated.

  • ApiKeyAuth — API token authentication. Pass the token directly: Authorization: token. For OAuth2 Bearer tokens use: Authorization: Bearer token.
  • BearerAuth — OAuth2 Bearer token obtained via Device Authorization Grant (RFC 8628).
  • BasicAuth — Deprecated. Basic authentication with username and password. Only allowed on specific endpoints for generating API tokens.

Paths & Operations 4

Across 4 paths, the API surfaces 4 operations — 4 POST. Each is listed below with its method, path, parameters, and response codes.

OAuth 4

OAuth2 Device Authorization Grant flow.

POST
/oauth/device_authorization
Initiate Device Authorization
initiateDeviceAuthorization body → 200400
POST
/oauth/token
Request Token
requestToken body → 200400
POST
/oauth/revoke
Revoke Token
revokeToken body → 200
POST
/oauth/revoke_by_hash
Revoke Token by Hash
revokeTokenByHash body → 200

Schemas 5

The contract defines 5 schemas that model the data the API accepts and returns. The most detailed are DeviceAuthorizationResponse (6 properties), TokenResponse (5 properties), DeviceAuthorizationRequest (4 properties), Error (3 properties). Each schema is shown below with its type and property counts.

TokenResponse
object
5 properties
TokenRequest
object
3 properties 3 required
DeviceAuthorizationResponse
object
6 properties
DeviceAuthorizationRequest
object
4 properties 1 required
Error
object
3 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

hex-pm-oauth-api-openapi.yml Raw ↑

Other APIs Hex.pm publishes across the network.

Hex.pm API Keys API
Hex.pm Authentication API
Hex.pm Documentation API
Hex.pm Index API
Hex.pm Organizations API
Hex.pm Package Owners API
Hex.pm Packages API
Hex.pm Releases API
Hex.pm Repositories API
Hex.pm Users API
Hex.pm Utilities API