Get On Board Authentication API

Token-based authentication

Operations 1

POST /api/v0/auth_tokens Refresh auth token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/get-on-board-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

get-on-board-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Get on Board Authentication API
  version: 0.1.0
  description: The Get on Board API provides access to the data inside Get on Board, the leading recruitment platform for tech professionals in Latin America.
servers:
- url: https://www.getonbrd.com
  description: Production
- url: https://sandbox.getonbrd.dev
  description: Sandbox
tags:
- name: Authentication
  description: Token-based authentication
paths:
  /api/v0/auth_tokens:
    post:
      summary: Refresh auth token
      tags:
      - Authentication
      security:
      - BearerAuth: []
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                refresh_token: YOUR_REFRESH_TOKEN
              required:
              - refresh_token
            example:
              refresh_token: YOUR_REFRESH_TOKEN
      responses:
        '200':
          description: Exchanges a valid refresh token for a new JWT access token.
          content:
            application/json:
              schema:
                type: object
                properties:
                  token: YOUR_JWT_TOKEN
                  refresh_token: YOUR_REFRESH_TOKEN
                required:
                - token
                - refresh_token
              example:
                token: YOUR_JWT_TOKEN
                refresh_token: YOUR_REFRESH_TOKEN
        '400':
          description: Exchanges a valid refresh token for a new JWT access token.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: 'param is missing or the value is empty or invalid: Missing refresh token parameter'
                code: bad_request
        '401':
          description: Exchanges a valid refresh token for a new JWT access token.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: (Status 401) Refresh token expired
                code: unauthorized
      operationId: refreshAuthToken
      description: Send a valid `refresh_token` to receive a new short-lived JWT `token`. Keep using the same `refresh_token` until it expires.
components:
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: 'Company authentication for private endpoints. Send `Authorization: Bearer <api_key>`.'
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Professional JWT token obtained via /api/v0/auth_tokens
    BoardSecretKey:
      type: http
      scheme: bearer
      bearerFormat: Board secret
      description: 'Board+ HMAC secret key. Send `Authorization: Bearer <board_secret_key>`. The legacy query-string form (`?secret_key=...`) is still accepted by the server but is discouraged because secrets leak into logs, browser history, and referrers.'
x-tagGroups:
- name: Public
  tags:
  - Categories
  - Companies
  - Countries
  - Headcounts
  - Industries
  - Insights
  - Modalities
  - Perks
  - Regions
  - Search
  - Seniorities
  - Tags
  - Tenant Cities
- name: Private
  tags:
  - Applications
  - Company shells
  - Jobs
  - Matching
  - Processes
  - Professionals
  - Webhooks
- name: Authentication
  tags:
  - Authentication
- name: Board+
  tags:
  - Board+