Authentik Core API

Users, groups, applications, tokens, brands, application entitlements and authenticated sessions — the identity records and the objects users see.

Operations 78

GET /core/application_entitlements/ Core application entitlements list #
POST /core/application_entitlements/ Core application entitlements create #
GET /core/application_entitlements/{pbm_uuid}/ Core application entitlements retrieve #
PUT /core/application_entitlements/{pbm_uuid}/ Core application entitlements update #
PATCH /core/application_entitlements/{pbm_uuid}/ Core application entitlements partial update #
DELETE /core/application_entitlements/{pbm_uuid}/ Core application entitlements destroy #
GET /core/application_entitlements/{pbm_uuid}/used_by/ Core application entitlements used by list #
GET /core/application_entitlements/requestable/ Core application entitlements requestable list #
GET /core/applications/ Core applications list #
POST /core/applications/ Core applications create #
GET /core/applications/{slug}/ Core applications retrieve #
PUT /core/applications/{slug}/ Core applications update #
PATCH /core/applications/{slug}/ Core applications partial update #
DELETE /core/applications/{slug}/ Core applications destroy #
GET /core/applications/{slug}/check_access/ Core applications check access retrieve #
GET /core/applications/{slug}/used_by/ Core applications used by list #
GET /core/applications/requestable/ Core applications requestable list #
GET /core/authenticated_sessions/ Core authenticated sessions list #
GET /core/authenticated_sessions/{uuid}/ Core authenticated sessions retrieve #
DELETE /core/authenticated_sessions/{uuid}/ Core authenticated sessions destroy #
GET /core/authenticated_sessions/{uuid}/used_by/ Core authenticated sessions used by list #
DELETE /core/authenticated_sessions/bulk_delete/ Core authenticated sessions bulk delete destroy #
GET /core/brands/ Core brands list #
POST /core/brands/ Core brands create #
GET /core/brands/{brand_uuid}/ Core brands retrieve #
PUT /core/brands/{brand_uuid}/ Core brands update #
PATCH /core/brands/{brand_uuid}/ Core brands partial update #
DELETE /core/brands/{brand_uuid}/ Core brands destroy #
GET /core/brands/{brand_uuid}/used_by/ Core brands used by list #
GET /core/brands/current/ Core brands current retrieve #
GET /core/groups/ Core groups list #
POST /core/groups/ Core groups create #
GET /core/groups/{group_uuid}/ Core groups retrieve #
PUT /core/groups/{group_uuid}/ Core groups update #
PATCH /core/groups/{group_uuid}/ Core groups partial update #
DELETE /core/groups/{group_uuid}/ Core groups destroy #
POST /core/groups/{group_uuid}/add_user/ Core groups add user create #
POST /core/groups/{group_uuid}/remove_user/ Core groups remove user create #
GET /core/groups/{group_uuid}/used_by/ Core groups used by list #
GET /core/object_attributes/ Core object attributes list #
POST /core/object_attributes/ Core object attributes create #
GET /core/object_attributes/{attribute_id}/ Core object attributes retrieve #
PUT /core/object_attributes/{attribute_id}/ Core object attributes update #
PATCH /core/object_attributes/{attribute_id}/ Core object attributes partial update #
DELETE /core/object_attributes/{attribute_id}/ Core object attributes destroy #
GET /core/tokens/ Core tokens list #
POST /core/tokens/ Core tokens create #
GET /core/tokens/{identifier}/ Core tokens retrieve #
PUT /core/tokens/{identifier}/ Core tokens update #
PATCH /core/tokens/{identifier}/ Core tokens partial update #
DELETE /core/tokens/{identifier}/ Core tokens destroy #
POST /core/tokens/{identifier}/set_key/ Core tokens set key create #
GET /core/tokens/{identifier}/used_by/ Core tokens used by list #
GET /core/tokens/{identifier}/view_key/ Core tokens view key retrieve #
PUT /core/transactional/applications/ Core transactional applications update #
GET /core/users/ Core users list #
POST /core/users/ Core users create #
GET /core/users/{id}/ Core users retrieve #
PUT /core/users/{id}/ Core users update #
PATCH /core/users/{id}/ Core users partial update #
DELETE /core/users/{id}/ Core users destroy #
POST /core/users/{id}/impersonate/ Core users impersonate create #
POST /core/users/{id}/recovery/ Core users recovery create #
POST /core/users/{id}/recovery_email/ Core users recovery email create #
POST /core/users/{id}/set_password/ Core users set password create #
POST /core/users/{id}/set_password_hash/ Core users set password hash create #
GET /core/users/{id}/used_by/ Core users used by list #
POST /core/users/account_lockdown/ Core users account lockdown create #
POST /core/users/export/ Core users export create #
GET /core/users/impersonate_end/ Core users impersonate end retrieve #
GET /core/users/me/ Core users me retrieve #
GET /core/users/paths/ Core users paths retrieve #
POST /core/users/service_account/ Core users service account create #
POST /core/users/switch/ Core users switch create #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/authentik-core-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

authentik-core-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: authentik Core API
  version: 2026.11.0-rc1
  description: Making authentication simple.
  contact:
    email: hello@goauthentik.io
  license:
    name: MIT
    url: https://github.com/goauthentik/authentik/blob/main/LICENSE
  x-source-url: https://api.goauthentik.io/schema.yml
  x-last-validated: '2026-09-04'
servers:
- url: /api/v3
tags:


# --- truncated at 32 KB (168 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/openapi/authentik-core-api-openapi.yml