How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Scalar auth API

The auth API from Scalar — 27 operation(s) for auth.

Scalar auth API is one of 30 APIs that Scalar publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Authentication. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 28 operations across 27 paths, and defines 17 schemas. It is described by OpenAPI 3.1.1, at version 1.0.1.

28 operations 27 paths 17 schemas 2 DELETE8 GET18 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.1
API Version
1.0.1
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Scalar auth API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (BearerAuth). By default, every request must be authenticated.

Paths & Operations 28

Across 27 paths, the API surfaces 28 operations — 2 DELETE, 8 GET, 18 POST. Each is listed below with its method, path, parameters, and response codes.

auth 28
GET
/me
Get a users basic information
getme → 200400401403404422500
POST
/login/email
Login with email password flow
postloginEmail body → 200400401403404422500
POST
/login/email-signup
Register with email password flow
postloginEmailSignup body → 200400401403404422500
POST
/login/email-otp
Send an OTP verification code to the email
postloginEmailOtp body → 200400401403404422500
POST
/login/email-otp/verify
Verify OTP
postloginEmailOtpVerify body → 200400401403404422500
POST
/login/refresh
Refresh an access token and set the team uid token
postloginRefresh body → 200400401403404422500
POST
/login/exchange
Exchange the short lived URL token for access/refresh tokens
postloginExchange body → 200400401403404422500
POST
/login/get-exchange
Gets an exchange token that can be used to redirect a user with auth credentials to different domain
postloginGetExchange body → 200400401403404422500
POST
/login/request-password-reset
Request reset password
postloginRequestPasswordReset body → 200400401403404422500
POST
/login/reset-password
Verify password reset request
postloginResetPassword body → 200400401403404422500
POST
/login/change-password
Change password for authenticated user
postloginChangePassword body → 200400401403404422500
POST
/login/personal-token/generate
Generate a new personal token
postloginPersonalTokenGenerate body → 200400401403404422500
POST
/login/personal-token/access
Generate a new access token from a personal token
postloginPersonalTokenAccess body → 200400401403404422500
POST
/login/personal-token/{uid}/revoke
Revoke a personal token
postloginPersonalTokenUidRevoke 1 param → 200400401403404422500
DELETE
/login/personal-token/{uid}
Delete a personal token
deleteloginPersonalTokenUid 1 param → 200400401403404422500
GET
/identity-provider/{uid}
Get an identity provider configuration for a team
getidentityProviderUid 1 param → 200400401403404422500
DELETE
/identity-provider/{uid}
Delete an identity provider configuration for a team
deleteidentityProviderUid 1 param → 200400401403404422500
POST
/identity-provider
Add an identity provider configuration for a team
postidentityProvider body → 200400401403404422500
POST
/identity-provider/update
Update an identity provider configuration for a team
postidentityProviderUpdate body → 200400401403404422500
GET
/saml/metadata
Get base SP SAML metadata
getsamlMetadata → 200400401403404422500
GET
/saml/idp/{uid}/metadata
Get SAML IdP-specific connection metadata
getsamlIdpUidMetadata 1 param → 200400401403404422500
GET
/saml/idp/{uid}/login
SAML connection login route
getsamlIdpUidLogin 4 params → 200400401403404422500
GET
/saml/logout
SAML logout route
getsamlLogout → 200400401403404422500
POST
/saml/acs
SAML ACS route
postsamlAcs body → 200400401403404422500
POST
/saml/initiate
SAML initiate route
postsamlInitiate body → 200400401403404422500
GET
/saml/cert/signing
Return SAML public signing cert
getsamlCertSigning → 200400401403404422500
GET
/saml/cert/encryption
Return SAML public encryption cert
getsamlCertEncryption → 200400401403404422500
POST
/events/auth/vacuum-refresh-tokens
Clean-up unused refresh tokens
posteventsAuthVacuumRefreshTokens body → 200400401403404422500

Schemas 17

The contract defines 17 schemas that model the data the API accepts and returns. The most detailed are user (11 properties), identity-provider-record (11 properties), team-ref (3 properties), 404 (2 properties). Each schema is shown below with its type and property counts.

user
object
11 properties 9 required
team-image
string
team-ref
object
3 properties 2 required
sso-resource
string
nanoid
string
404
object
2 properties 2 required
401
object
2 properties 2 required
slug
string
token-response
object
2 properties 2 required
500
object
2 properties 2 required
email
string
400
object
2 properties 2 required
team-name
string
403
object
2 properties 2 required
timestamp
integer
422
object
2 properties 2 required
identity-provider-record
object
11 properties 11 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

scalar-auth-api-openapi.yml Raw ↑

Other APIs Scalar publishes across the network.

Scalar API References
Scalar API Client
Scalar Docs
Scalar Registry
Scalar SDKs
Scalar CLI
Scalar access-groups API
Scalar analytics API
Scalar api-docs API
Scalar docs API
Scalar Docs Projects API
Scalar Forgejo API
Where this information came from

This is an independent, third-party profile of Scalar auth API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.