Clerk OAuth2 Identity Provider API

Requests for the OAuth2 authorization flow.

Business capability
Identity & Access Management BC-620.20

Operations 10

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

GET /oauth/authorize Start an OAuth2 authorization via GET redirect · Request OAuth2 Authorization #
Ask an LLM
“How do I send a user to the authorization endpoint to get an OAuth code using a GET link?”
“Does the authorize URL support PKCE code challenges as query parameters?”
Tell an agent
Build a GET authorize request for client {client_id} with response type {response_type}.
Request authorization in the query string for client {client_id}, type {response_type}, scope {scope}, redirect {redirect_uri}.
POST /oauth/authorize Start an OAuth2 authorization via form POST · Request OAuth2 Authorization #
Ask an LLM
“Can I post the authorization request as a form body instead of query parameters?”
“How do I submit an OAuth2 authorize request with a POST body including a nonce?”
Tell an agent
POST an authorization request for client {client_id} with response type {response_type}.
Submit a form-posted authorize request for {client_id}, type {response_type}, state {state}.
POST /oauth/register Dynamically register an OAuth client · Register OAuth 2.0 Client #
Ask an LLM
“How can an app register itself as an OAuth client without manual setup?”
“Does the identity provider support RFC 7591 dynamic client registration?”
Tell an agent
Register an OAuth client with redirect URIs {redirect_uris}.
Register OAuth client {client_name} with redirect URIs {redirect_uris} and scope {scope}.
POST /oauth/token Exchange a code or refresh token for tokens · Get OAuth2 Token #
Ask an LLM
“How do I trade an authorization code for access and ID tokens?”
“Can I use a refresh token grant to get a new access token?”
Tell an agent
Exchange authorization code {code} for tokens with grant type {grant_type}.
Get a new access token using refresh token {refresh_token} (grant {grant_type}).
GET /oauth/userinfo Get user info with an access token via GET · Get User Info After OAuth2 Flow #
Ask an LLM
“How do I fetch the signed-in user's profile claims with an OAuth access token using GET?”
“Which endpoint returns OIDC userinfo on a plain GET request?”
Tell an agent
Get the userinfo for my OAuth access token with a GET request.
Fetch OIDC user claims via GET.
POST /oauth/userinfo Get user info with an access token via POST · Get User Info After OAuth2 Flow #
Ask an LLM
“Can I request OIDC userinfo with a POST instead of a GET?”
“Which userinfo variant accepts a POST request from my OAuth client?”
Tell an agent
POST my access token to the userinfo endpoint to get my profile claims.
Use the POST variant of userinfo to fetch OIDC claims.
POST /oauth/token_info Introspect an access or refresh token · Get Information for an Access or Refresh Token #
Ask an LLM
“How do I check whether an OAuth token is still active and what scopes it has?”
“Can I introspect a refresh token as well as an access token?”
Tell an agent
Introspect token {token}.
Get info for token {token} with hint {token_type_hint}.
POST /oauth/token/revoke Revoke an OAuth2 token · Revoke OAuth2 Token #
Ask an LLM
“How do I invalidate an OAuth access or refresh token that was issued to my app?”
“Do confidential clients need Basic auth to revoke a token?”
Tell an agent destructive · confirm first
Revoke OAuth token {token}.
Revoke token {token} as a {token_type_hint}.
GET /v1/me/oauth/consent/{client_id} Get consent scopes for an OAuth app · Get Consent Information #
Ask an LLM
“What scopes will a user be asked to consent to for an OAuth application?”
“Can I restrict the consent info to only the scopes being requested?”
Tell an agent
Show the consent scopes for OAuth client {client_id}.
Get consent information for client {client_id} limited to scope {scope}.
POST /v1/me/oauth/consent/{client_id} Submit a user's OAuth consent decision · Submit OAuth2 Consent Decision #
Ask an LLM
“How do I build a custom consent screen that records whether the user approved?”
“Can a user grant consent to an OAuth app on behalf of an organization?”
Tell an agent
Submit consent {consented} for OAuth client {client_id}.
Approve client {client_id} for organization {organization_id} (consented {consented}).

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/clerk-com-oauth2-identity-provider-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

clerk-com-oauth2-identity-provider-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Clerk Frontend OAuth2 Identity Provider API
  version: v1
  description: The Clerk REST Frontend API, meant to be accessed from a browser or native environment.
  x-logo:
    url: https://clerk.com/_next/image?url=%2Fimages%2Fclerk-logo.svg&w=96&q=75
    altText: Clerk docs
    href: https://clerk.com/docs
  contact:
    email: support@clerk.com
    name: Clerk Team
    url: https://clerk.com/support
  termsOfService: https://clerk.com/terms
  license:
    name: MIT
    url: https://github.com/clerk/javascript/blob/main/LICENSE
servers:
- url: https://{domain}.clerk.accounts.dev
  variables:
    domain:
      default: example-destined-camel-13
      description: Your Development Instance Frontend API Domain.
security:
- {}
- DevBrowser: []
- ProductionBrowser: []
- ProductionNativeApp: []
  ProductionNativeFlag: []
tags:


# --- truncated at 32 KB (46 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/clerk-com/refs/heads/main/openapi/clerk-com-oauth2-identity-provider-api-openapi.yml