How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Transmit Security Auth API

The Auth API from Transmit Security — 10 operation(s) for auth.

Transmit Security Auth API is one of 9 APIs that Transmit Security publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 7 JSON Schema definitions.

Tagged areas include Authentication. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and 7 JSON Schemas.

This API exposes 10 operations across 10 paths, and defines 25 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 5 base URLs: https://api.sbx.transmitsecurity.io/cis, https://api.transmitsecurity.io/cis, https://api.eu.transmitsecurity.io/cis, https://api.ca.transmitsecurity.io/cis, https://api.au.transmitsecurity.io/cis.

10 operations 10 paths 25 schemas 10 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.transmitsecurity.io
Authentication
HTTP Bearer, HTTP Bearer, OAuth 2.0, OAuth 2.0, OAuth 2.0
Resource Areas
1

Authentication & Security 5

Transmit Security Auth API declares 5 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearer). It accepts HTTP bearer tokens (JWT) (UserAccessToken). It supports OAuth 2.0 (AdminAccessToken) using the clientCredentials flow. It supports OAuth 2.0 (ClientAccessToken) using the clientCredentials flow. It supports OAuth 2.0 (OrgAdminAccessToken) using the clientCredentials flow.

  • UserAccessToken — A token returned upon end-user authentication, which provides access to resources and data for the user and app for which it was generated
  • AdminAccessToken — A token generated by a management application using the [token endpoint](/openapi/token.openapi/other/getaccesstoken). It provides access to all resources for…
  • ClientAccessToken — A token generated by an end-user application using the [token endpoint](/openapi/token.openapi/other/getaccesstoken). It provides access to resources and data…
  • OrgAdminAccessToken — A token returned upon B2B authentication for a user that has the organizationAdmin or organizationCreator role.

Paths & Operations 10

Across 10 paths, the API surfaces 10 operations — 10 POST. Each is listed below with its method, path, parameters, and response codes.

Auth 10
POST
/v1/auth/link/email/send
Send email link
sendMagicLinkEmail body → 200400403404
POST
/v1/auth/link/email/authenticate
Authenticate email link
authenticateMagicLink body → 200400
POST
/v1/auth/otp/send
Send OTP
sendOTP body → 200400403404
POST
/v1/auth/otp/authenticate
Authenticate OTP
authenticateOTP body → 200400403
POST
/v1/auth/links/email
Send email link
SendEmail body → 200400404
POST
/v1/auth/otp/email
Send email OTP
sendEmailOtp body → 200400404
POST
/v1/auth/otp/email/validation
Validate email OTP
validateEmailOtp body → 200400
POST
/v1/auth/otp/sms
Send SMS OTP
sendSmsOtp body → 200400404
POST
/v1/auth/otp/sms/validation
Validate SMS OTP
validateSms body → 200400
POST
/v1/auth/logout
Logout
logout → 200400401

Schemas 25

The contract defines 25 schemas that model the data the API accepts and returns. The most detailed are ApiOtpInitRequestDto (12 properties), ApiOtpTokenRequestDto (10 properties), ApiSendOtpEmailRequestInput (10 properties), ApiMagicLinkInitWithIdentifierRequestDto (10 properties). Each schema is shown below with its type and property counts.

ApiSendLoginEmailInput
object
9 properties 2 required
NotFoundHttpError
object
2 properties 2 required
BadRequestException
object
ApiValidateAuthEmailOtpInput
object
4 properties 2 required
ApiValidateAuthSmsOtpInput
object
4 properties 2 required
EmailContentAttributes
object
9 properties 1 required
ApiTokenResponse
object
6 properties 4 required
ClientAttributes
object
2 properties
InvalidTokenHttpError
object
2 properties 2 required
ApiSendOtpEmailRequestInput
object
10 properties 2 required
ApiSendAuthSmsResponse
object
2 properties 1 required
ApiSendOtpEmailResponse
object
2 properties 1 required
ApiOtpInitRequestDto
object
12 properties 3 required
RedirectUriResponse
object
1 property 1 required
ApiTokenRequestClaims
object
2 properties
ApiMagicLinkTokenRequestDto
object
8 properties 1 required
ApiOtpTokenRequestDto
object
10 properties 3 required
ApiSendOtpResponse
object
3 properties 1 required
BadRequestHttpError
object
2 properties 2 required
ApiSendEmailResponse
object
1 property 1 required
ApiLogoutResponse
object
1 property 1 required
ApiMagicLinkInitWithIdentifierRequestDto
object
10 properties 3 required
ApiSendAuthSmsOtpInput
object
9 properties 3 required
BaseSmsOtpInput
object
2 properties
ApiMagicLinkInitWithEmailRequestDto
object
9 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

transmit-security-auth-api-openapi.yml Raw ↑

Other APIs Transmit Security publishes across the network.

Mosaic Orchestration API
Transmit Security Applications API
Transmit Security Manage API
Transmit Security Organizations API
Transmit Security Recommendation API
Transmit Security Token API
Transmit Security Users API
Transmit Security Verification API
Where this information came from

This is an independent, third-party profile of Transmit Security Auth API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.