Automattic Auth API

The auth API from Automattic — 8 operation(s) for auth.

Operations 8

POST /wpcom/v2/auth/qr-code-app/approve POST /wpcom/v2/auth/qr-code-app/approve #
POST /wpcom/v2/auth/qr-code-app/exchange POST /wpcom/v2/auth/qr-code-app/exchange #
POST /wpcom/v2/auth/qr-code-app/scan POST /wpcom/v2/auth/qr-code-app/scan #
GET /wpcom/v2/auth/qr-code-app/session-status GET /wpcom/v2/auth/qr-code-app/session-status #
GET /wpcom/v2/auth/qr-code-app/status GET /wpcom/v2/auth/qr-code-app/status #
POST /wpcom/v2/auth/qr-code-app/token POST /wpcom/v2/auth/qr-code-app/token #
POST /wpcom/v2/auth/qr-code/authenticate POST /wpcom/v2/auth/qr-code/authenticate #
POST /wpcom/v2/auth/qr-code/validate POST /wpcom/v2/auth/qr-code/validate #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/automattic-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

automattic-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: WordPress.com REST API — wpcom/v2 namespace Auth API
  version: v2
  description: Derived by API Evangelist from the WordPress.com REST API route index published at https://public-api.wordpress.com/wpcom/v2/. Paths, HTTP methods, and parameter names/types/descriptions/defaults are taken verbatim from that index. Response schemas are not published in the route index, so successful responses are described but not schematised; the error envelope was observed live on public-api.wordpress.com.
  contact:
    name: Automattic
    url: https://developer.wordpress.com/docs/api/
  x-derived-from: https://public-api.wordpress.com/wpcom/v2/
  x-derived-by: API Evangelist enrichment pipeline
servers:
- url: https://public-api.wordpress.com
security:
- bearerAuth: []
tags:
- name: auth
paths:
  /wpcom/v2/auth/qr-code-app/approve:
    post:
      operationId: postWpcomV2AuthQrCodeAppApprove
      summary: POST /wpcom/v2/auth/qr-code-app/approve
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
  /wpcom/v2/auth/qr-code-app/exchange:
    post:
      operationId: postWpcomV2AuthQrCodeAppExchange
      summary: POST /wpcom/v2/auth/qr-code-app/exchange
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
  /wpcom/v2/auth/qr-code-app/scan:
    post:
      operationId: postWpcomV2AuthQrCodeAppScan
      summary: POST /wpcom/v2/auth/qr-code-app/scan
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
  /wpcom/v2/auth/qr-code-app/session-status:
    get:
      operationId: getWpcomV2AuthQrCodeAppSessionStatus
      summary: GET /wpcom/v2/auth/qr-code-app/session-status
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
  /wpcom/v2/auth/qr-code-app/status:
    get:
      operationId: getWpcomV2AuthQrCodeAppStatus
      summary: GET /wpcom/v2/auth/qr-code-app/status
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
  /wpcom/v2/auth/qr-code-app/token:
    post:
      operationId: postWpcomV2AuthQrCodeAppToken
      summary: POST /wpcom/v2/auth/qr-code-app/token
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
  /wpcom/v2/auth/qr-code/authenticate:
    post:
      operationId: postWpcomV2AuthQrCodeAuthenticate
      summary: POST /wpcom/v2/auth/qr-code/authenticate
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                token:
                  type: string
                  default: ''
                data:
                  type: string
                  default: ''
  /wpcom/v2/auth/qr-code/validate:
    post:
      operationId: postWpcomV2AuthQrCodeValidate
      summary: POST /wpcom/v2/auth/qr-code/validate
      tags:
      - auth
      responses:
        '200':
          description: OK
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPRestError'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                token:
                  type: string
                  default: ''
                data:
                  type: string
                  default: ''
components:
  schemas:
    WPRestError:
      type: object
      description: WordPress REST API error envelope (observed on public-api.wordpress.com).
      properties:
        code:
          type: string
          example: rest_unauthorized
        message:
          type: string
          example: Authentication required.
        data:
          type: object
          properties:
            status:
              type: integer
              example: 401
  securitySchemes:
    oauth2:
      type: oauth2
      description: WordPress.com OAuth 2.1, per https://public-api.wordpress.com/.well-known/openid-configuration
      flows:
        authorizationCode:
          authorizationUrl: https://public-api.wordpress.com/oauth2-1/authorize
          tokenUrl: https://public-api.wordpress.com/oauth2-1/token
          refreshUrl: https://public-api.wordpress.com/oauth2-1/token
          scopes:
            global: ''
            auth: ''
            openid: ''
            profile: ''
            email: ''
            users: ''
            sites: ''
            posts: ''
            comments: ''
            taxonomy: ''
            follow: ''
            sharing: ''
            freshly-pressed: ''
            notifications: ''
            insights: ''
            read: ''
            stats: ''
            media: ''
            menus: ''
            batch: ''
            videos: ''
    bearerAuth:
      type: http
      scheme: bearer