Euler Finance Auth API
Authentication and authorization conventions used across the API, including API keys, admin secrets, and rate-limit behavior.
Authentication and authorization conventions used across the API, including API keys, admin secrets, and rate-limit behavior.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/euler-auth-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Euler Data API (V3) Auth API
version: 3.0.0
description: API specification for Euler Data v3.
servers:
- url: /
description: Current environment
security: []
tags:
- name: Auth
description: Authentication and authorization conventions used across the API, including API keys, admin secrets, and rate-limit behavior.
paths:
/v3/auth/login:
get:
tags:
- Auth
summary: Start platform-operator Google SSO
description: Redirects the browser to Google OAuth/OIDC and sets a signed OAuth state cookie.
x-status: implemented
responses:
'302':
description: Redirect to configured Google OAuth authorization URL.
headers:
Location:
description: Google authorization URL.
schema:
type: string
format: uri
Set-Cookie:
description: Signed OAuth state cookie with httpOnly, SameSite, path, and expiry.
schema:
type: string
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
operationId: startPlatformAuthLogin
/v3/auth/callback:
get:
tags:
- Auth
summary: Complete platform-operator Google SSO callback
description: Validates state, nonce, Google ID-token claims, and active platform-admin access.
x-status: implemented
parameters:
- name: code
in: query
required: true
schema:
type: string
description: OAuth authorization code. Never returned in responses.
- name: state
in: query
required: true
schema:
type: string
description: OAuth anti-forgery state bound to the signed state cookie.
responses:
'302':
description: Successful callback; session and CSRF cookies are set, then browser is redirected.
headers:
Location:
description: Configured post-login redirect URL.
schema:
type: string
format: uri
Set-Cookie:
description: Signed httpOnly session cookie, readable CSRF cookie, and cleared OAuth state cookie.
schema:
type: string
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
'400':
description: Invalid callback, state, nonce, or ID token.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'403':
description: Google identity is not an active platform admin.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
operationId: completePlatformAuthCallback
/v3/auth/session:
get:
tags:
- Auth
summary: Get current platform-operator session
x-status: implemented
security:
- PlatformSession: []
responses:
'200':
description: Active platform-admin session identity.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
$ref: '#/components/schemas/PlatformAuthSession'
meta:
$ref: '#/components/schemas/PaginationMeta'
'401':
description: Missing, invalid, or expired platform-admin session.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'403':
description: Authenticated session exists, but platform-admin access is not active.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
operationId: getPlatformAuthSession
/v3/auth/logout:
post:
tags:
- Auth
summary: End current platform-operator session
x-status: implemented
security:
- PlatformSession: []
PlatformCsrf: []
responses:
'200':
description: Session cookies were cleared.
headers:
Set-Cookie:
description: Expired session and CSRF cookies.
schema:
type: string
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
type: object
required:
- loggedOut
properties:
loggedOut:
type: boolean
meta:
$ref: '#/components/schemas/PaginationMeta'
'401':
description: Invalid signed platform-admin session.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'403':
description: Missing or mismatched CSRF token, or inactive platform-admin access.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
operationId: logoutPlatformAuthSession
/v3/platform-admins:
post:
tags:
- Auth
summary: Grant platform-admin access
description: 'Creates an active platform-admin access row for a Google email address.
Requires a valid platform session and CSRF token because this is an unsafe
cookie-authenticated write.'
x-status: implemented
security:
- PlatformSession: []
PlatformCsrf: []
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformAdminAccessRequest'
responses:
'200':
description: Existing revoked platform-admin access was reactivated.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
$ref: '#/components/schemas/PlatformAdminCreateAccessResult'
meta:
$ref: '#/components/schemas/PaginationMeta'
'201':
description: Platform-admin access was created.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
$ref: '#/components/schemas/PlatformAdminCreateAccessResult'
meta:
$ref: '#/components/schemas/PaginationMeta'
'400':
description: Malformed JSON request body.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'401':
description: Missing, invalid, or expired platform-admin session.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'403':
description: Inactive platform-admin access, missing CSRF token, or mismatched CSRF token.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'409':
description: Platform-admin access already exists.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'422':
description: Missing or invalid Google email.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
operationId: createPlatformAdminAccess
/v3/platform-admins/revoke:
post:
tags:
- Auth
summary: Revoke platform-admin access
description: 'Soft-revokes platform-admin access for a Google email address. Requires a
valid platform session and CSRF token because this is an unsafe
cookie-authenticated write.'
x-status: implemented
security:
- PlatformSession: []
PlatformCsrf: []
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformAdminAccessRequest'
responses:
'200':
description: Platform-admin access was revoked.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
$ref: '#/components/schemas/PlatformAdminRevokeAccessResult'
meta:
$ref: '#/components/schemas/PaginationMeta'
'400':
description: Malformed JSON request body.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'401':
description: Missing, invalid, or expired platform-admin session.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'403':
description: Inactive platform-admin access, missing CSRF token, or mismatched CSRF token.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'404':
description: Platform-admin access was not found.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'409':
description: Platform-admin access was already revoked.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'422':
description: Missing or invalid Google email.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
operationId: revokePlatformAdminAccess
/v3/toolbox/admin/api-keys:
get:
tags:
- Auth
summary: List API keys for toolbox Admin
description: Lists API key metadata for the toolbox Admin screen. Requires an active platform-admin session and a Google email present in `TOOLBOX_ADMIN_EMAILS`.
x-status: implemented
security:
- PlatformSession: []
responses:
'200':
description: API key metadata visible to toolbox admins.
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
type: array
items:
$ref: '#/components/schemas/ApiKeyResponse'
meta:
$ref: '#/components/schemas/PaginationMeta'
'401':
$ref: '#/components/responses/Error401'
'403':
$ref: '#/components/responses/Error403'
'500':
$ref: '#/components/responses/Error500'
operationId: getToolboxAdminApiKeys
/v3/admin/api-keys:
post:
tags:
- Auth
summary: Create an API key (admin)
x-status: implemented
security:
- AdminSecret: []
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/ApiKeyCreateRequest'
responses:
'201':
description: API key created
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
properties:
data:
$ref: '#/components/schemas/ApiKeyCreateResponse'
'400':
$ref: '#/components/responses/Error400'
'401':
$ref: '#/components/responses/Error401'
'403':
$ref: '#/components/responses/Error403'
'413':
$ref: '#/components/responses/Error413'
'415':
$ref: '#/components/responses/Error415'
'500':
$ref: '#/components/responses/Error500'
operationId: postAdminApiKeys
get:
tags:
- Auth
summary: List API keys (admin)
x-status: implemented
security:
- AdminSecret: []
responses:
'200':
description: API keys
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/ApiKeyResponse'
'401':
$ref: '#/components/responses/Error401'
'403':
$ref: '#/components/responses/Error403'
'500':
$ref: '#/components/responses/Error500'
operationId: getAdminApiKeys
/v3/admin/api-keys/{id}:
get:
tags:
- Auth
summary: Get API key by id (admin)
x-status: implemented
security:
- AdminSecret: []
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
'200':
description: API key
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
properties:
data:
$ref: '#/components/schemas/ApiKeyResponse'
'401':
$ref: '#/components/responses/Error401'
'403':
$ref: '#/components/responses/Error403'
'404':
$ref: '#/components/responses/Error404'
'500':
$ref: '#/components/responses/Error500'
operationId: getAdminApiKeysById
patch:
tags:
- Auth
summary: Update API key (admin)
x-status: implemented
security:
- AdminSecret: []
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
name:
type: string
rateLimit:
type: integer
isActive:
type: boolean
keyType:
type: string
enum:
- standard
- curator
scopeMode:
type: string
enum:
- all_vaults
- allowlist
vaultAllowlist:
type: array
items:
type: object
required:
- chainId
- vaultAddress
properties:
chainId:
type: integer
vaultAddress:
type: string
responses:
'200':
description: Updated
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
properties:
data:
type: object
'400':
$ref: '#/components/responses/Error400'
'401':
$ref: '#/components/responses/Error401'
'403':
$ref: '#/components/responses/Error403'
'404':
$ref: '#/components/responses/Error404'
'413':
$ref: '#/components/responses/Error413'
'415':
$ref: '#/components/responses/Error415'
'500':
$ref: '#/components/responses/Error500'
operationId: patchAdminApiKeysById
delete:
tags:
- Auth
summary: Revoke API key (admin)
x-status: implemented
security:
- AdminSecret: []
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
'200':
description: Revoked
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
properties:
data:
type: object
'401':
$ref: '#/components/responses/Error401'
'403':
$ref: '#/components/responses/Error403'
'404':
$ref: '#/components/responses/Error404'
'500':
$ref: '#/components/responses/Error500'
operationId: deleteAdminApiKeysById
/v3/admin/api-keys/{id}/usage:
get:
tags:
- Auth
summary: Usage stats for an API key (admin)
x-status: implemented
security:
- AdminSecret: []
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: days
in: query
required: false
schema:
type: integer
responses:
'200':
description: Usage stats
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
type: object
properties:
data:
$ref: '#/components/schemas/ApiKeyUsageResponse'
'401':
$ref: '#/components/responses/Error401'
'403':
$ref: '#/components/responses/Error403'
'404':
$ref: '#/components/responses/Error404'
'500':
$ref: '#/components/responses/Error500'
operationId: getAdminApiKeysByIdUsage
components:
schemas:
ApiKeyCreateResponse:
type: object
required:
- message
- key
- keyPrefix
- id
- name
- keyType
- rateLimit
properties:
message:
type: string
key:
type: string
keyPrefix:
type: string
id:
type: string
name:
type: string
keyType:
type: string
enum:
- standard
- curator
scopeMode:
type: string
enum:
- all_vaults
- allowlist
nullable: true
vaultAllowlist:
type: array
items:
type: object
required:
- chainId
- vaultAddress
properties:
chainId:
type: integer
vaultAddress:
type: string
rateLimit:
type: integer
expiresAt:
type: string
format: date-time
nullable: true
ApiKeyCreateRequest:
type: object
required:
- name
properties:
name:
type: string
ownerEmail:
type: string
format: email
keyType:
type: string
enum:
- standard
- curator
default: standard
scopeMode:
type: string
enum:
- all_vaults
- allowlist
vaultAllowlist:
type: array
items:
type: object
required:
- chainId
- vaultAddress
properties:
chainId:
type: integer
vaultAddress:
type: string
rateLimit:
type: integer
expiresInDays:
type: integer
PlatformAdminRevokeAccessResult:
type: object
required:
- admin
- state
properties:
admin:
$ref: '#/components/schemas/PlatformAdminAccess'
state:
type: string
enum:
- revoked
PlatformAdminAccess:
type: object
required:
- id
- googleEmail
- createdAt
- revokedAt
properties:
id:
type: string
format: uuid
googleEmail:
type: string
format: email
createdAt:
type: string
format: date-time
revokedAt:
type: string
format: date-time
nullable: true
ApiKeyUsageResponse:
type: object
required:
- period
- summary
- endpoints
properties:
period:
type: object
required:
- days
- since
properties:
days:
type: integer
since:
type: string
format: date-time
summary:
type: object
required:
- totalRequests
- avgResponseTimeMs
- errorCount
properties:
totalRequests:
type: integer
avgResponseTimeMs:
type: integer
errorCount:
type: integer
endpoints:
type: array
items:
type: object
required:
- endpoint
- method
- count
- avgResponseTime
properties:
endpoint:
type: string
method:
type: string
count:
type: integer
avgResponseTime:
type: integer
ApiKeyResponse:
type: object
required:
- id
- name
- keyType
- rateLimit
- isActive
- createdAt
properties:
id:
type: string
keyPrefix:
type: string
name:
type: string
ownerEmail:
type: string
nullable: true
keyType:
type: string
enum:
- standard
- curator
scopeMode:
type: string
enum:
- all_vaults
- allowlist
nullable: true
vaultAllowlist:
type: array
items:
type: object
required:
- chainId
- vaultAddress
properties:
chainId:
type: integer
vaultAddress:
type: string
rateLimit:
type: integer
isActive:
type: boolean
createdAt:
type: string
format: date-time
lastUsedAt:
type: string
format: date-time
nullable: true
expiresAt:
type: string
format: date-time
nullable: true
PlatformAdminCreateAccessResult:
type: object
required:
- admin
- state
properties:
admin:
$ref: '#/components/schemas/PlatformAdminAccess'
state:
type: string
enum:
- created
- reactivated
ErrorResponse:
type: object
required:
- error
properties:
error:
type: object
required:
- code
- message
- requestId
properties:
code:
type: string
description: 'Domain error code. Examples:
- INVALID_ADDRESS
- CHAIN_NOT_SUPPORTED
- VAULT_NOT_FOUND
- TOKEN_NOT_FOUND
- ACCOUNT_NOT_FOUND
- VALIDATION_ERROR
- RATE_LIMIT_EXCEEDED
- UNSUPPORTED_MEDIA_TYPE
- UNAUTHORIZED
- FORBIDDEN
- INTERNAL_ERROR
'
message:
type: string
requestId:
type: string
details:
type: object
additionalProperties: true
PaginationMeta:
type: object
required:
- timestamp
properties:
total:
type: integer
description: Exact total count when the endpoint provides one.
hasMore:
type: boolean
description: Indicates whether another page exists beyond the current page.
offset:
type: integer
limit:
type: integer
description: Echoed page size after endpoint-side clamping.
timestamp:
type: string
format: date-time
chainId:
type: string
description: Comma-separated chain IDs for multi-chain responses.
PlatformAuthSession:
type: object
required:
- platformAdminId
- googleEmail
- googleSubject
- active
- expiresAt
properties:
platformAdminId:
type: string
format: uuid
googleEmail:
type: string
format: email
googleSubject:
type: string
active:
type: boolean
const: true
expiresAt:
type: string
format: date-time
PlatformAdminAccessRequest:
type: object
additionalProperties: false
required:
- googleEmail
properties:
googleEmail:
type: string
format: email
description: Google Workspace email address to grant or revoke.
headers:
X-Request-Id:
description: Request identifier for tracing.
schema:
type: string
responses:
Error500:
description: Internal server error
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Error403:
description: Forbidden
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Error400:
description: Bad request
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Error413:
description: Request body too large
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Error415:
description: Unsupported media type
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Error401:
description: Unauthorized
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Error404:
description: Not found
headers:
X-Request-Id:
$ref: '#/components/headers/X-Request-Id'
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
securitySchemes:
ApiKeyAuth:
type: apiKey
in: header
name: X-API-Key
description: API key authentication (optional; higher rate limits).
BearerAuth:
type: http
scheme: bearer
bearerFormat: API key
description: 'Alternative to X-API-Key using Authorization: Bearer <key>'
AdminSecret:
type: apiKey
in: header
name: X-Admin-Secret
description: Admin secret (server-to-server) for API key management.
PlatformSession:
type: apiKey
in: cookie
name: euler_platform_session
description: Signed, httpOnly platform-operator browser session cookie.
PlatformCsrf:
type: apiKey
in: header
name: X-CSRF-Token
description: Double-submit CSRF token required for unsafe cookie-authenticated methods.