Observe.AI Authentication API
OAuth 2.0, which stands for “Open Authorization”, is a standard design to allow a website or application to access resources hosted by other web apps on behalf of a userNote: If you have been using Basic Auth for the APIs, we request you to switch to OAuth2.0 based Auth for the APIs by 31-Dec-2022. Detailed instructions to create API Credentials and make the switch to OAuth are documented as below. Please reach out to your CSM for more details. OAuth App Credential Flow The App Credentials flow is recommended for server-side (AKA confidential) client applications with no end user, which normally describes machine-to-machine communication. Your application needs to securely store its app ID and secret and pass those to Observe Authentication Api in exchange for an access token. Steps required for generating access token 1. API Credential Generation: To get access for API credentials, please contact help@observe.ai. AppId and AppSecret required to create access tokens, you can generate max of 3 apps. - Select New App Id and App Secret. - Add your app name. - Download the credentials, these can not viewed/downloaded later. 2. Access Token You can create accessToken, using AppId and AppSecret from step 1. Access Token expires in 2 hrs, needs to be created again after expiry time. The 'Create Auth Token API' API has a rate limit of 1500 requests per day. The video in Getting Started outlines these steps in detail
Observe.AI Authentication API is one of 7 APIs that Observe.AI publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
This API exposes 16 JSON Schema definitions.
Tagged areas include Authentication. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, a getting-started guide, authentication docs, rate-limit docs, and 16 JSON Schemas.
This API exposes 1 operation across 1 path, and defines 3 schemas. It is described by OpenAPI 3.2.0.
Requests are made against a single base URL, https://{base_url}.
Metadata
The identity and technical contract details declared by the specification.
Authentication & Security 5
Observe.AI Authentication API declares
5 security schemes
for authenticating requests.
It accepts HTTP bearer tokens (JWT) (bearerAuth).
It defines a object scheme (DsrDeleteRequest).
It defines a object scheme (DsrRule).
It defines a object scheme (DsrDeleteResponse).
It defines a object scheme (DsrStatusResponse).
Paths & Operations 1
Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.
OAuth 2.0, which stands for “Open Authorization”, is a standard design to allow a website or application to access resources hosted by other web apps on behalf of a user Note : If…
Schemas 3
The contract defines 3 schemas that model the data the API accepts and returns. The most detailed are ErrorMessage (2 properties), OauthTokenRequest (2 properties), OauthTokenResponse (2 properties). Each schema is shown below with its type and property counts.
Specification
The full machine-readable OpenAPI contract behind this narrative.
Source
More from Observe.AI 6
Other APIs Observe.AI publishes across the network.
This is an independent, third-party profile of Observe.AI Authentication API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.