# dotCMS Dot Auth API

**Canonical:** https://apis.io/apis/dotcms/dotcms-dotauth-api/  
**Provider:** dotCMS — https://apis.io/providers/dotcms/  
**Base URL:** https://demo.dotcms.com/api  
**Documentation:** https://dev.dotcms.com/docs/build/apis/api-basics/rest-apis

dotCMS Dot Auth API is one of 73 APIs that [dotCMS](https://apis.io/providers/dotcms/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

OAuth/OIDC and SAML authentication: per-site configuration (SYSTEM_HOST is the global default) and headless OIDC token exchange

## Operations (15)

| Method | Path | Summary |
|---|---|---|
| POST | `/api/v1/dotauth/oauth/exchange` | Exchange an OIDC id_token for a dotAuth session-ref |
| OPTIONS | `/api/v1/dotauth/oauth/exchange` | Exchange preflight |
| GET | `/api/v1/dotauth/sites/{hostId}` | Get the dotAuth configuration for a site |
| PUT | `/api/v1/dotauth/sites/{hostId}` | Save (upsert) the dotAuth configuration for a site |
| DELETE | `/api/v1/dotauth/sites/{hostId}` | Clear the dotAuth configuration for a site |
| PUT | `/api/v1/dotauth/headless` | Save the system-level headless token-exchange configuration |
| DELETE | `/api/v1/dotauth/headless` | Clear the system-level headless token-exchange configuration |
| POST | `/api/v1/dotauth/discover/oidc` | Fetch and parse an OIDC discovery document |
| POST | `/api/v1/dotauth/export` | Export all dotAuth AppSecrets |
| POST | `/api/v1/dotauth/fetch/saml-metadata` | Fetch SAML IdP metadata XML from a URL |
| GET | `/api/v1/dotauth/saml/metadata/{hostId}` | Download SAML SP metadata XML for a site |
| POST | `/api/v1/dotauth/import` | Import dotAuth AppSecrets |
| GET | `/api/v1/dotauth/sites` | List all sites with their dotAuth status |
| POST | `/api/v1/dotauth/sessionrefs/revoke` | Revoke all dotAuth sessionRefs |
| DELETE | `/api/v1/dotauth/oauth/session` | Invalidate the caller's dotAuth session-ref |

## Machine-readable artifacts (7)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/dotcms/refs/heads/main/openapi/dotcms-dotauth-api-openapi.yml
- **Documentation** — https://dev.dotcms.com/docs/build/apis/api-basics/rest-apis
- **DeveloperPortal** — https://dev.dotcms.com/
- **APIReference** — https://dev.dotcms.com/docs/build/apis/rest-apis/api-playground
- **ErrorCatalog** — https://raw.githubusercontent.com/api-evangelist/dotcms/refs/heads/main/errors/dotcms-problem-types.yml
- **DataModel** — https://raw.githubusercontent.com/api-evangelist/dotcms/refs/heads/main/data-model/dotcms-data-model.yml
- **Conventions** — https://raw.githubusercontent.com/api-evangelist/dotcms/refs/heads/main/conventions/dotcms-conventions.yml

## Other dotCMS APIs (12)

- [dotCMS GraphQL API](https://apis.io/apis/dotcms/graphql/)
- [dotCMS Accessibility Agent API](https://apis.io/apis/dotcms/dotcms-accessibility-agent-api/)
- [dotCMS Accessibility Checker API](https://apis.io/apis/dotcms/dotcms-accessibility-checker-api/)
- [dotCMS Administration API](https://apis.io/apis/dotcms/dotcms-administration-api/)
- [dotCMS AI API](https://apis.io/apis/dotcms/dotcms-ai-api/)
- [dotCMS Announcements API](https://apis.io/apis/dotcms/dotcms-announcements-api/)
- [dotCMS API Token API](https://apis.io/apis/dotcms/dotcms-api-token-api/)
- [dotCMS Apps API](https://apis.io/apis/dotcms/dotcms-apps-api/)
- [dotCMS Authentication API](https://apis.io/apis/dotcms/dotcms-authentication-api/)
- [dotCMS Browser Tree API](https://apis.io/apis/dotcms/dotcms-browser-tree-api/)
- [dotCMS Bundle API](https://apis.io/apis/dotcms/dotcms-bundle-api/)
- [dotCMS Cache Management API](https://apis.io/apis/dotcms/dotcms-cache-management-api/)

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/dotcms/dotcms-dotauth-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/dotcms/.
