OpenAPI Specification
openapi: 3.0.3
info:
title: Cube Agents Auth API
version: 1.0.0 (1.0)
description: "#### General Description\nAn API to access underlying Cube functionality. These endpoints are the same endpoints\nthat support Cube's universal add-ons and a plethora of integrations meaning you'll be able to interact with your\nCube data in many powerful ways. Visit the API section of Cube's [Help Center](https://help.cubesoftware.com/hc/en-us/sections/18205290556180-Custom-Integrations)\nfor more usage guides on how you can use this API to integrate with Cube to accomplish various tasks!\n\n#### Versioning\nAll requests to the API require a version to be configured via an `Accept` Header. The value of this Header should look like this:\n```\nAccept: application/json; version=1.0\n```\nNote that the version number may differ depending on which version of the endpoint is needed.\n\n#### Response Structure\nThe general response structure of Cube's API endpoints will contain a `\"data\"` and `\"metadata\"` root level key:\n```json\n{\n \"data\": { ... object data or list of objects ... },\n \"metadata\": {\n \"status\": 200,\n \"message\": \"Potential message with additional context\",\n \"error\": false,\n \"code\": \"\"\n }\n}\n```\n\n#### Rate Limiting\nAll endpoints have a rate limit configured, most of them default to 5/s.\nWhen the rate limit is encountered, a 429 HTTP code will be returned.\n\n#### Error Handling\nIn the event an error occurs, the response will typically look like this:\n```json\n{\n \"data\": {},\n \"metadata\": {\n \"status\": 400,\n \"message\": \"Some error message\",\n \"error\": true,\n \"code\": \"SOME_ERROR_CODE\"\n }\n}\n```\n"
termsOfService: https://www.cubesoftware.com/terms-of-service
servers:
- url: https://api.cubesoftware.com
description: Production API URL
tags:
- name: Auth
paths:
/auth/devices:
get:
operationId: auth_devices_list
description: Returns all confirmed multi-factor authentication devices for the current user.
summary: List enabled MFA devices
parameters:
- in: header
name: X-Company-ID
schema:
type: string
description: Associates request with company
required: true
tags:
- Auth
security:
- OAuth2: []
- {}
responses:
'200':
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/MfaDevice'
description: ''
/auth/embed-token:
post:
operationId: auth_embed_token_create
description: Creates a short-lived, single-use embed token for authenticating embedded portal pages in iframes or headless browsers.
summary: Create an embed token
tags:
- Auth
security:
- OAuth2: []
- {}
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/EmbedTokenCreateResponse'
description: ''
/auth/embed-token/exchange:
post:
operationId: auth_embed_token_exchange_create
description: Exchanges a short-lived embed token for a standard OAuth2 access token. Returns the same payload shape as the PKCE token endpoint.
summary: Exchange an embed token for an OAuth2 access token
tags:
- Auth
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/EmbedTokenExchangeRequest'
application/x-www-form-urlencoded:
schema:
$ref: '#/components/schemas/EmbedTokenExchangeRequest'
multipart/form-data:
schema:
$ref: '#/components/schemas/EmbedTokenExchangeRequest'
required: true
responses:
'200':
content:
application/json:
schema:
type: object
properties:
access_token:
type: string
token_type:
type: string
expires_in:
type: integer
scope:
type: string
company_id:
type: string
format: uuid
description: OAuth2 access token response
'401':
description: Invalid or expired embed token
components:
schemas:
EmbedTokenCreateResponse:
type: object
properties:
embed_token:
type: string
required:
- embed_token
MfaDevice:
type: object
properties:
persistent_id:
type: string
name:
type: string
device_type:
type: string
readOnly: true
confirmed:
type: boolean
required:
- confirmed
- device_type
- name
- persistent_id
EmbedTokenExchangeRequest:
type: object
properties:
embed_token:
type: string
required:
- embed_token
securitySchemes:
OAuth2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://portal.cubesoftware.com/o/authorize/
tokenUrl: https://api.cubesoftware.com/o/token/
scopes: {}
description: Standard Cube OAuth 2.0 flow