How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Zoca Auth API

The auth API from Zoca — 41 operation(s) for auth.

Zoca Auth API is one of 193 APIs that Zoca publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Authentication. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 41 operations across 41 paths, and defines 1 schema. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 2 base URLs: https://api.zoca.ai, https://tasks.zoca.ai.

41 operations 41 paths 1 schemas 29 GET12 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.zoca.ai
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Zoca Auth API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (access-token).

  • access-token — Enter JWT token in the format Bearer

Paths & Operations 41

Across 41 paths, the API surfaces 41 operations — 29 GET, 12 POST. Each is listed below with its method, path, parameters, and response codes.

auth 41
GET
/auth/me
The caller's identity and per-context permissions
t_value → 200401
GET
/auth
Health check for auth service
t_value → 200
GET
/auth/check
Check authentication status
t_value → 200
POST
/auth/google-token-exchange
Exchange Google token (client-side flow)
t_value → 201
GET
/auth/google-callback
Google Authentication callback
t_value → 200
GET
/auth/google-auth-url
Google Authentication URL
t_value 2 params → 200
GET
/auth/gmail-auth-url
Gmail Authentication URL
t_value 1 param → 200
GET
/auth/win/authorize
Win Standalone Authentication URL
t_value 2 params → 200
GET
/auth/win/google-callback
Win Standalone Google Authentication callback
t_value → 200
GET
/auth/google-dummyurl
Get Google dummy URL for testing
t_value → 200
GET
/auth/google-browser-simulator
Simulate Google browser authentication
t_value → 200
GET
/auth/square/authorize
Square OAuth Authorization URL
t_value → 200400
GET
/auth/square/callback
Square OAuth callback
t_value → 200
POST
/auth/square/refresh/{entityId}
Refresh Square access token
t_value → 201
POST
/auth/square/revoke
Revoke Square access token
t_value → 201
GET
/auth/google-auth-status
Get Google Business Profile authentication status
t_value → 200
POST
/auth/refresh-jwt
Refresh JWT token
t_value → 201
POST
/auth/refresh-token
Refresh authentication token
t_value → 201
GET
/auth/validate
Validate JWT token
t_value → 200
GET
/auth/meta/authorize
Get Meta OAuth authorization URL
t_value → 200
GET
/auth/meta/callback
Meta OAuth callback
t_value → 200
GET
/auth/instagram/authorize
Instagram OAuth Authorization URL
t_value → 200
GET
/auth/instagram/callback
Instagram OAuth Callback
t_value → 302
GET
/auth/tiktok/authorize
TikTok OAuth Authorization URL
t_value → 200
GET
/auth/tiktok/callback
TikTok OAuth Callback
t_value → 302
GET
/auth/acuity/authorize
Get Acuity OAuth authorization URL
t_value → 200
GET
/auth/acuity/callback
Acuity OAuth callback
t_value → 200
POST
/auth/mindbody/register
Register Mindbody site and connect
t_value → 201
GET
/auth/meevo/locations
List Meevo tenant locations
t_value → 200
POST
/auth/meevo/register
Register Meevo location and connect
t_value → 201
GET
/auth/mindbody/activation-status
Poll-safe Mindbody activation status
t_value → 200
GET
/auth/mindbody/connect
Connect existing Mindbody site
t_value → 200
POST
/auth/magic-link/request
Request a magic link for passwordless login
t_value → 200429
POST
/auth/magic-link/verify
Verify a magic link token and get auth tokens
t_value → 200400
GET
/tasks/api/v1/auth/google/url
Get Google OAuth URL
t_value 2 params → 200
GET
/tasks/api/v1/auth/google/callback
Google OAuth callback
t_value → 200302
GET
/tasks/api/v1/auth/me
Get current user profile
t_value → 200401
POST
/tasks/api/v1/auth/refresh
Refresh authentication token
t_value → 200401
POST
/tasks/api/v1/auth/logout
Logout and invalidate session
t_value → 200
GET
/tasks/api/v1/auth/sessions
Get all active sessions for the current user
t_value → 200
POST
/tasks/api/v1/auth/sessions/revoke-all
Revoke all sessions for the current user
t_value → 200

Schemas 1

The contract defines 1 schema that model the data the API accepts and returns. The most detailed is e (6 properties). Each schema is shown below with its type and property counts.

e
object
6 properties 3 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

zoca-auth-api-openapi.yml Raw ↑

Other APIs Zoca publishes across the network.

Zoca ACM API
Zoca Acuity API
Zoca Addon Groups API
Zoca Addons API
Zoca Aeo Lead Magnet API
Zoca Agents API
Zoca API Keys API
Zoca App API
Zoca App Blocker API
Zoca App Blocker Updates API
Zoca Approvals API
Zoca Billing API
Where this information came from

This is an independent, third-party profile of Zoca Auth API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.