How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Scalar Auth API

The auth API from Scalar — 27 operation(s) for auth.

Scalar Auth API is one of 39 APIs that Scalar publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 6 JSON Schema definitions.

Tagged areas include Authentication. The published artifact set on APIs.io includes an OpenAPI specification and 6 JSON Schemas.

This API exposes 30 operations across 29 paths, and defines 32 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against a single base URL, https://api.scalar.com/core.

30 operations 29 paths 32 schemas 2 DELETE9 GET19 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Server
https://api.scalar.com/core
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Scalar Auth API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (BearerAuth). By default, every request must be authenticated.

Paths & Operations 30

Across 29 paths, the API surfaces 30 operations — 2 DELETE, 9 GET, 19 POST. Each is listed below with its method, path, parameters, and response codes.

Auth 30
GET
/me
Getme
getme → 200400401403404422500
POST
/login/email
Postlogin email
postloginEmail body → 200400401403404422500
POST
/login/email-signup
Postlogin email signup
postloginEmailSignup body → 200400401403404422500
POST
/login/email-otp
Postlogin email otp
postloginEmailOtp body → 200400401403404422500
POST
/login/email-otp/verify
Postlogin email otp verify
postloginEmailOtpVerify body → 200400401403404422500
POST
/login/refresh
Postlogin refresh
postloginRefresh body → 200400401403404422500
POST
/login/exchange
Postlogin exchange
postloginExchange body → 200400401403404422500
POST
/login/get-exchange
Postlogin get exchange
postloginGetExchange body → 200400401403404422500
POST
/login/request-password-reset
Postlogin request password reset
postloginRequestPasswordReset body → 200400401403404422500
POST
/login/reset-password
Postlogin reset password
postloginResetPassword body → 200400401403404422500
POST
/login/change-password
Postlogin change password
postloginChangePassword body → 200400401403404422500
POST
/login/personal-token/generate
Postlogin personal token generate
postloginPersonalTokenGenerate body → 200400401403404422500
POST
/login/personal-token/access
Postlogin personal token access
postloginPersonalTokenAccess body → 200400401403404422500
POST
/login/personal-token/{uid}/revoke
Postlogin personal token uid revoke
postloginPersonalTokenUidRevoke 1 param → 200400401403404422500
DELETE
/login/personal-token/{uid}
Deletelogin personal token uid
deleteloginPersonalTokenUid 1 param → 200400401403404422500
GET
/identity-provider/{uid}
Getidentity provider uid
getidentityProviderUid 1 param → 200400401403404422500
DELETE
/identity-provider/{uid}
Deleteidentity provider uid
deleteidentityProviderUid 1 param → 200400401403404422500
POST
/identity-provider
Postidentity provider
postidentityProvider body → 200400401403404422500
POST
/identity-provider/update
Postidentity provider update
postidentityProviderUpdate body → 200400401403404422500
GET
/saml/metadata
Getsaml metadata
getsamlMetadata → 200400401403404422500
GET
/saml/idp/{uid}/metadata
Getsaml idp uid metadata
getsamlIdpUidMetadata 1 param → 200400401403404422500
GET
/saml/idp/{uid}/login
Getsaml idp uid login
getsamlIdpUidLogin 4 params → 200400401403404422500
GET
/saml/logout
Getsaml logout
getsamlLogout → 200400401403404422500
POST
/saml/acs
Postsaml acs
postsamlAcs body → 200400401403404422500
POST
/saml/initiate
Postsaml initiate
postsamlInitiate body → 200400401403404422500
GET
/saml/cert/signing
Getsaml cert signing
getsamlCertSigning → 200400401403404422500
GET
/saml/cert/encryption
Getsaml cert encryption
getsamlCertEncryption → 200400401403404422500
POST
/events/auth/vacuum-refresh-tokens
Postevents auth vacuum refresh tokens
posteventsAuthVacuumRefreshTokens body → 200400401403404422500
GET
/hosting-authenticate
Get hosting authenticate
getHostingAuthenticate 1 param → 200400401403404422500
POST
/logout
Post logout
postLogout body → 200400401403404422500

Schemas 32

The contract defines 32 schemas that model the data the API accepts and returns. The most detailed are user_2 (12 properties), identity-provider-record (11 properties), user (11 properties), identity-provider-record_2 (11 properties). Each schema is shown below with its type and property counts.

nanoid
string
404
object
2 properties 2 required
timestamp
integer
team-ref
object
3 properties 2 required
slug
string
403
object
2 properties 2 required
email
string
user
object
11 properties 9 required
422
object
2 properties 2 required
401
object
2 properties 2 required
400
object
2 properties 2 required
token-response
object
2 properties 2 required
sso-resource
string
team-name
string
500
object
2 properties 2 required
team-image
string
identity-provider-record
object
11 properties 11 required
nanoid_2
string
404_2
object
2 properties 2 required
timestamp_2
integer
slug_2
string
403_2
object
2 properties 2 required
email_2
string
user_2
object
12 properties 9 required
422_2
object
2 properties 2 required
401_2
object
2 properties 2 required
400_2
object
2 properties 2 required
sso-resource_2
string
team-name_2
string
500_2
object
2 properties 2 required
team-image_2
string
identity-provider-record_2
object
11 properties 11 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

scalar-auth-api-openapi.yml Raw ↑

Other APIs Scalar publishes across the network.

Scalar API References
Scalar API Client
Scalar Docs
Scalar Registry
Scalar SDKs
Scalar CLI
Scalar Access Groups API
Scalar Analytics API
Scalar API Docs API
Scalar Docs API
Scalar Docs Projects API
Scalar Forgejo API
Where this information came from

This is an independent, third-party profile of Scalar Auth API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.