CyberArk Identity Authentication API
The Authentication API from CyberArk Identity — 3 operation(s) for authentication.
The Authentication API from CyberArk Identity — 3 operation(s) for authentication.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/cyberark-identity-authentication-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: CyberArk Identity REST Authentication API
version: 2026-05
description: 'CyberArk Identity (formerly Idaptive) REST API. Provides
authentication, OAuth/OIDC token issuance, user and organization
management, extended user attributes/schema, and SCIM v2 user/group
provisioning against a CyberArk Identity tenant.
Best-effort spec derived from publicly indexed CyberArk Identity
developer documentation (api-docs.cyberark.com, docs.cyberark.com,
and third-party API directory listings). The authoritative reference
is https://api-docs.cyberark.com/identity-docs-api/docs/identity-apis.
The host should be set to your CyberArk Identity tenant URL —
e.g. https://aab1234.id.cyberark.cloud.
'
contact:
name: CyberArk Developer Hub
url: https://api-docs.cyberark.com/identity-docs-api/docs/identity-apis
license:
name: Proprietary
servers:
- url: https://{tenant}.id.cyberark.cloud
description: CyberArk Identity tenant
variables:
tenant:
default: aab1234
description: Your CyberArk Identity tenant prefix.
security:
- BearerAuth: []
tags:
- name: Authentication
paths:
/Security/StartAuthentication:
post:
tags:
- Authentication
summary: Begin an interactive authentication session
description: 'Starts an authentication session for a user identified by username
and tenant. Returns the available authentication mechanisms; the
client must complete the flow with /Security/AdvanceAuthentication
within five minutes.
'
security: []
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- User
properties:
User:
type: string
description: Username (UPN).
Version:
type: string
example: '1.0'
responses:
'200':
description: Authentication session started
content:
application/json:
schema:
$ref: '#/components/schemas/AuthChallengeResult'
/Security/AdvanceAuthentication:
post:
tags:
- Authentication
summary: Submit a mechanism response and advance the auth session
security: []
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- SessionId
- MechanismId
properties:
SessionId:
type: string
MechanismId:
type: string
Answer:
type: string
Action:
type: string
example: Answer
responses:
'200':
description: Auth advanced (challenge or success)
content:
application/json:
schema:
$ref: '#/components/schemas/AuthChallengeResult'
/Security/Logout:
post:
tags:
- Authentication
summary: Log out the current session
responses:
'200':
description: Logged out
components:
schemas:
AuthChallengeResult:
type: object
properties:
success:
type: boolean
Result:
type: object
properties:
SessionId:
type: string
TenantId:
type: string
Challenges:
type: array
items:
type: object
properties:
Mechanisms:
type: array
items:
type: object
properties:
Name:
type: string
MechanismId:
type: string
AnswerType:
type: string
Summary:
type: string
Message:
type: string
nullable: true
Exception:
type: string
nullable: true
ErrorCode:
type: string
nullable: true
ErrorID:
type: string
nullable: true
securitySchemes:
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
description: OAuth 2.0 / OIDC bearer token issued by /OAuth2/Token/{appId}.
BasicAuth:
type: http
scheme: basic
description: HTTP Basic with OAuth client credentials, used only for /OAuth2/Token/{appId}.
externalDocs:
description: CyberArk Identity API reference
url: https://api-docs.cyberark.com/identity-docs-api/docs/identity-apis