Archera O Auth API

OAuth 2.0 authorization endpoints for third-party integrations

Operations 8

GET /oauth/authorize Redirect to React consent page #
POST /oauth/authorize Handle user authorization decision from React consent page #
POST /oauth/token Issue access tokens #
GET /oauth/sessions List all active OAuth sessions for the current user #
DELETE /oauth/sessions/{token_id} Revoke a specific OAuth session by token ID #
POST /oauth/revoke-all Revoke all OAuth sessions (refresh tokens) for the current user across all… #
POST /oauth/revoke Revoke an access token or refresh token #
POST /oauth/register Create oauth register #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/archera-oauth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

archera-oauth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: '### Welcome to the Archera.ai API documentation.'
  title: Archera.ai OAuth API
  version: v1.0.0
tags:
- name: OAuth
  description: OAuth 2.0 authorization endpoints for third-party integrations
paths:
  /oauth/authorize:
    get:
      responses:
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      summary: Redirect to React consent page
      description: 'Query Parameters (handled by Authlib):

        client_id: OAuth client identifier

        redirect_uri: Where to redirect after authorization

        response_type: Must be ''code''

        scope: Space-separated list of requested scopes

        state: CSRF protection token (optional but recommended)

        code_challenge: PKCE code challenge

        code_challenge_method: PKCE method (usually ''S256'')


        Returns:

        Redirect to React consent page with OAuth params and client info'
      tags:
      - OAuth
      operationId: getOauthAuthorize
      x-operation-id-source: derived
    post:
      responses:
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      summary: Handle user authorization decision from React consent page
      description: 'Query Parameters:

        All OAuth params from GET (client_id, redirect_uri, state, etc.)


        Form Parameters:

        confirm: ''yes'' to authorize, ''no'' to deny


        Returns:

        Redirect to client with authorization code or error'
      tags:
      - OAuth
      operationId: postOauthAuthorize
      x-operation-id-source: derived
  /oauth/token:
    post:
      responses:
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      summary: Issue access tokens
      description: 'Form Parameters (authorization_code grant):

        grant_type: Must be ''authorization_code''

        code: Authorization code from /authorize

        redirect_uri: Must match original request

        client_id: OAuth client identifier

        code_verifier: PKCE code verifier


        Form Parameters (refresh_token grant):

        grant_type: Must be ''refresh_token''

        refresh_token: Valid refresh token

        client_id: OAuth client identifier


        Returns:

        JSON response with access_token (JWT), refresh_token, expires_in, etc.'
      tags:
      - OAuth
      operationId: postOauthToken
      x-operation-id-source: derived
  /oauth/sessions:
    get:
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/OAuthSessionResponse'
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      summary: List all active OAuth sessions for the current user
      description: 'Returns:

        List of active sessions including client info, creation time, and scope'
      tags:
      - OAuth
      operationId: getOauthSessions
      x-operation-id-source: derived
  /oauth/sessions/{token_id}:
    parameters:
    - in: path
      name: token_id
      required: true
      schema:
        type: string
        format: uuid
    delete:
      responses:
        '204':
          description: No Content
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      summary: Revoke a specific OAuth session by token ID
      description: 'Args:

        token_id: UUID of the OAuth token to revoke


        Returns:

        204 No Content on success

        404 Not Found if session doesn''t exist or doesn''t belong to user'
      tags:
      - OAuth
      operationId: deleteOauthSessionsByTokenId
      x-operation-id-source: derived
  /oauth/revoke-all:
    post:
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RevokeAllSessionsResponse'
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      summary: Revoke all OAuth sessions (refresh tokens) for the current user across all…
      description: 'Returns:

        JSON with message and count of revoked sessions'
      tags:
      - OAuth
      operationId: postOauthRevokeAll
      x-operation-id-source: derived
  /oauth/revoke:
    post:
      responses:
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      summary: Revoke an access token or refresh token
      description: 'Form Parameters:

        token: The token to revoke (access_token or refresh_token)

        token_type_hint: Optional hint about token type (''access_token'' or ''refresh_token'')


        Returns:

        200 response (always returns 200 per RFC 7009, even for invalid tokens)'
      tags:
      - OAuth
      operationId: postOauthRevoke
      x-operation-id-source: derived
  /oauth/register:
    post:
      responses:
        default:
          $ref: '#/components/responses/DEFAULT_ERROR'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
      tags:
      - OAuth
      summary: Create oauth register
      x-summary-source: derived
      operationId: postOauthRegister
      x-operation-id-source: derived
components:
  schemas:
    Error:
      type: object
      properties:
        code:
          type: integer
          description: Error code
        status:
          type: string
          description: Error name
        message:
          type: string
          description: Error message
        errors:
          type: object
          description: Errors
          additionalProperties: {}
      additionalProperties: false
    RevokeAllSessionsResponse:
      type: object
      properties:
        message:
          type: string
        count:
          type: integer
      required:
      - count
      - message
      additionalProperties: false
    OAuthSessionResponse:
      type: object
      properties:
        token_id:
          type: string
          pattern: '[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}\Z'
        client_name:
          type: string
        client_id:
          type: string
        created_at:
          type: integer
        scope:
          type: string
      required:
      - client_id
      - client_name
      - created_at
      - scope
      - token_id
      additionalProperties: false
    ApiErrorResponse:
      type: object
      properties:
        message:
          type: string
        detail: {}
        code:
          type:
          - string
          - 'null'
        url:
          type:
          - string
          - 'null'
        timestamp:
          type: string
        type:
          type: string
      required:
      - message
      - timestamp
      - type
  responses:
    DEFAULT_ERROR:
      description: Default error response
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'