Cube Auth API

The Auth API from Cube — 3 operation(s) for auth.

Operations 3

GET /auth/devices List enabled MFA devices #
POST /auth/embed-token Create an embed token #
POST /auth/embed-token/exchange Exchange an embed token for an OAuth2 access token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cubesoftware-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cubesoftware-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cube Auth API
  version: 1.0.0 (1.0)
  description: '#### General Description

    An API to access underlying Cube functionality.'
  termsOfService: https://www.cubesoftware.com/terms-of-service
servers:
- url: https://api.cubesoftware.com
  description: Production API URL
tags:
- name: Auth
paths:
  /auth/devices:
    get:
      operationId: auth_devices_list
      description: Returns all confirmed multi-factor authentication devices for the current user.
      summary: List enabled MFA devices
      parameters:
      - in: header
        name: X-Company-ID
        schema:
          type: string
        description: Associates request with company
        required: true
      tags:
      - Auth
      security:
      - OAuth2: []
      - {}
      responses:
        '200':
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/MfaDevice'
          description: ''
  /auth/embed-token:
    post:
      operationId: auth_embed_token_create
      description: Creates a short-lived, single-use embed token for authenticating embedded portal pages in iframes or headless browsers.
      summary: Create an embed token
      tags:
      - Auth
      security:
      - OAuth2: []
      - {}
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmbedTokenCreateResponse'
          description: ''
  /auth/embed-token/exchange:
    post:
      operationId: auth_embed_token_exchange_create
      description: Exchanges a short-lived embed token for a standard OAuth2 access token. Returns the same payload shape as the PKCE token endpoint.
      summary: Exchange an embed token for an OAuth2 access token
      tags:
      - Auth
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EmbedTokenExchangeRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/EmbedTokenExchangeRequest'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/EmbedTokenExchangeRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                type: object
                properties:
                  access_token:
                    type: string
                  token_type:
                    type: string
                  expires_in:
                    type: integer
                  scope:
                    type: string
                  company_id:
                    type: string
                    format: uuid
          description: OAuth2 access token response
        '401':
          description: Invalid or expired embed token
components:
  schemas:
    EmbedTokenExchangeRequest:
      type: object
      properties:
        embed_token:
          type: string
      required:
      - embed_token
    MfaDevice:
      type: object
      properties:
        persistent_id:
          type: string
        name:
          type: string
        device_type:
          type: string
          readOnly: true
        confirmed:
          type: boolean
      required:
      - confirmed
      - device_type
      - name
      - persistent_id
    EmbedTokenCreateResponse:
      type: object
      properties:
        embed_token:
          type: string
      required:
      - embed_token
  securitySchemes:
    OAuth2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://portal.cubesoftware.com/o/authorize/
          tokenUrl: https://api.cubesoftware.com/o/token/
          scopes: {}
      description: Standard Cube OAuth 2.0 flow