How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Logto My account API

Account routes provide functionality for managing user profile for the end user to interact directly with access tokens.

Logto My account API is one of 39 APIs that Logto publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include My Account. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and a GitHub repository.

This API exposes 29 operations across 22 paths. It is described by OpenAPI 3.2.0, at version Cloud.

Requests are made against a single base URL, https://[tenant_id].logto.app/.

29 operations 22 paths 0 schemas 6 DELETE9 GET5 PATCH7 POST2 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
Cloud
Server
https://[tenant_id].logto.app/
Authentication
OAuth 2.0
Resource Areas
1

Authentication & Security 1

Logto My account API declares 1 security scheme for authenticating requests. It supports OAuth 2.0 (OAuth2) using the clientCredentials flow, exposing 1 scope. By default, every request must be authenticated.

  • OAuth2 — Logto Management API is a comprehensive set of REST APIs that gives you the full control over Logto to suit your product needs and tech stack. To see the full…

Paths & Operations 29

Across 22 paths, the API surfaces 29 operations — 6 DELETE, 9 GET, 5 PATCH, 7 POST, 2 PUT. Each is listed below with its method, path, parameters, and response codes.

My account 29

Account routes provide functionality for managing user profile for the end user to interact directly with access tokens.

GET
/api/my-account
Get profile
GetProfile → 200401403
PATCH
/api/my-account
Update profile
UpdateProfile body → 200400401403422
PATCH
/api/my-account/profile
Update other profile
UpdateOtherProfile body → 200400401403
POST
/api/my-account/password
Update password
UpdatePassword body → 204400401403422
GET
/api/my-account/mfa-settings
Get MFA settings
GetMfaSettings → 200400401403
PATCH
/api/my-account/mfa-settings
Update MFA settings
UpdateMfaSettings body → 200400401403
GET
/api/my-account/logto-configs
Get logto config
GetLogtoConfig → 200400401403
PATCH
/api/my-account/logto-configs
Update logto config
UpdateLogtoConfig body → 200400401403
GET
/api/my-account/identities/{target}/access-token
Retrieve the access token issued by a third-party social provider
GetSocialIdentityAccessToken 1 param → 200400401403404422
PUT
/api/my-account/identities/{target}/access-token
Update the access token for a social identity by verification ID
UpdateSocialIdentityAccessTokenByVerificationId 1 param body → 200400401403422
GET
/api/my-account/sso-identities/{connectorId}/access-token
Retrieve the access token issued by a third-party enterprise SSO provider
GetEnterpriseSsoIdentityAccessToken 1 param → 200400401403404
POST
/api/my-account/primary-email
Update primary email
UpdatePrimaryEmail body → 204400401403422
DELETE
/api/my-account/primary-email
Delete primary email
DeletePrimaryEmail → 204400401403
POST
/api/my-account/primary-phone
Update primary phone
UpdatePrimaryPhone body → 204400401403422
DELETE
/api/my-account/primary-phone
Delete primary phone
DeletePrimaryPhone → 204400401403
POST
/api/my-account/identities
Add a user identity
AddUserIdentities body → 204400401403
DELETE
/api/my-account/identities/{target}
Delete a user identity
DeleteIdentity 1 param → 204400401403404
GET
/api/my-account/mfa-verifications
Get MFA verifications
GetMfaVerifications → 200400401403
POST
/api/my-account/mfa-verifications
Add a MFA verification
AddMfaVerification body → 204400401403422
PUT
/api/my-account/mfa-verifications/totp
Create or replace the authenticator app
CreateOrReplaceTotpMfaVerification body → 204400401403
POST
/api/my-account/mfa-verifications/totp-secret/generate
Generate a TOTP secret
GenerateTotpSecret → 200401403
POST
/api/my-account/mfa-verifications/backup-codes/generate
Generate backup codes
GenerateMyAccountBackupCodes → 200401403
GET
/api/my-account/mfa-verifications/backup-codes
Get backup codes
GetBackupCodes → 200401403404
PATCH
/api/my-account/mfa-verifications/{verificationId}/name
Update a MFA verification name
UpdateMfaVerificationName 1 param body → 200400401403
DELETE
/api/my-account/mfa-verifications/{verificationId}
Delete an MFA verification
DeleteMfaVerification 1 param → 204400401403
GET
/api/my-account/sessions
Get all active sessions
GetSessions → 200400401403500
DELETE
/api/my-account/sessions/{sessionId}
Revoke a session by ID
DeleteSessionById 2 params → 204400401403404500
GET
/api/my-account/grants
Get all active grants
GetGrants 1 param → 200400401403500
DELETE
/api/my-account/grants/{grantId}
Revoke a grant by ID
DeleteGrantById 1 param → 204400401403404500

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

logto-my-account-api-openapi.yml Raw ↑

Other APIs Logto publishes across the network.

Logto Account center API
Logto Applications API
Logto Audit logs API
Logto Authn API
Logto Captcha provider API
Logto Configs API
Logto Connector factories API
Logto Connectors API
Logto Custom phrases API
Logto Custom profile fields API
Logto Dashboard API
Logto Domains API
Where this information came from

This is an independent, third-party profile of Logto My account API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.