Harver OAUTH API

The oauth API from Harver — 3 operation(s) for oauth.

Operations 3

POST /oauth/token Start an authorized session #
POST /oauth/authenticate Validate auth token #
POST /oauth/userinfo Get identity claims for a user #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/harver-oauth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

harver-oauth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 1.37.0
  title: Harver Public OAuth API
  description: Public API of the Harver Platform available only for the Customers of Harver.
  contact:
    name: Harver Support Team
    email: support@harver.com
    url: https://support.harver.com
servers:
- url: https://api.harver.com/api/v1.0/
  description: Production Server
tags:
- name: OAuth
paths:
  /oauth/token:
    servers:
    - url: https://api.harver.com/
      description: Production Server
    post:
      summary: Start an authorized session
      description: 'Content-Type should be set to **application/x-www-form-urlencoded**

        ## Obtaining Tokens

        To obtain API tokens for any of your client applications, perform a POST operation to the `/oauth/token` endpoint with a payload in the following format

        ## Using client_credentials

        This type of authorization is used when applications require access to access their own resources, and is not done on behalf of a user. For instance, an Applicant Tracking System checking whether there are new applicants that have completed their application.

        ## Using an Access Token

        Once you have retrieved an Access Token, it can be used until the token expires or is revoked. To use it, send this token in the `Authorization` header when making requests to protected resources.


        Authorization: Bearer


        #### Example usage:


        curl -X GET \

        ''https://api.harver.com/api/v1.0/accounts'' \

        -H ''Authorization: Bearer eyJhbGciOiJIXzI1NiIsInR5cCI6IkpXVCJ9.eyJkYXRhIjp7InVzZXIiOnsiaWQiOiI1OWVkZDZhNvU4YzNlNDI3MDZjOWY3NjgifX0sImlhdCI6MTUzMzEzNDk5Mn0.otr7V1XMzF78LrB3oLRKUvTCxLqYM1CqKKp7UFDcPK8'''
      tags:
      - OAuth
      requestBody:
        description: Client ID, Client Secret, Grant Type that should be sent in the request body
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              additionalProperties: false
              required:
              - client_id
              - client_secret
              - grant_type
              properties:
                client_id:
                  description: Your Client ID, as provided by Harver
                  type: string
                client_secret:
                  description: Your Client Secret, as provided by Harver
                  type: string
                grant_type:
                  description: Must be set to client_credentials
                  type: string
                  enum:
                  - client_credentials
      responses:
        '200':
          description: A generated session
          content:
            application/json:
              schema:
                required:
                - accessToken
                - accessTokenExpiresAt
                - user
                - userProfile
                - client
                properties:
                  user:
                    required:
                    - id
                    properties:
                      id:
                        type: string
                  userProfile:
                    type: string
                  accessToken:
                    type: string
                  accessTokenExpiresAt:
                    type: string
                    format: date-time
                  client:
                    required:
                    - secret
                    - userId
                    - id
                    - roles
                    - redirectUris
                    - grants
                    properties:
                      secret:
                        type: string
                      userId:
                        type: string
                      roles:
                        type: array
                        items:
                          type: string
                      redirectUris:
                        type: array
                        items:
                          type: string
                      grants:
                        type: array
                        items:
                          type: string
                          enum:
                          - password
                          - client_credentials
                      id:
                        type: string
        '400':
          description: Invalid password or credentials
          content:
            application/json:
              schema:
                properties:
                  statusCode:
                    type: integer
                    format: int32
                  status:
                    type: integer
                    format: int32
                  code:
                    type: integer
                    format: int32
                  message:
                    type: string
                  name:
                    type: string
      operationId: postOauthToken
      x-operation-id-source: derived
  /oauth/authenticate:
    servers:
    - url: https://api.harver.com/
      description: Production Server
    post:
      summary: Validate auth token
      description: '## Validating a Token

        To validate a token, perform a POST operation to the `/oauth/authenticate` endpoint with authorization header `Bearer `

        ## Note: This endpoint is not recommended for public access / not supported

        #### Example usage:


        curl -X POST \

        ''https://api.harver.com/auth/authenticate'' \

        -H ''Authorization: Bearer eyJhbGciOiJIXzI1NiIsInR5cCI6IkpXVCJ9.eyJkYXRhIjp7InVzZXIiOnsiaWQiOiI1OWVkZDZhNvU4YzNlNDI3MDZjOWY3NjgifX0sImlhdCI6MTUzMzEzNDk5Mn0.otr7V1XMzF78LrB3oLRKUvTCxLqYM1CqKKp7UFDcPK8'''
      tags:
      - OAuth
      responses:
        '204':
          description: No content
        '400':
          description: Invalid token
          content:
            application/json:
              schema:
                properties:
                  statusCode:
                    type: integer
                    format: int32
                  status:
                    type: integer
                    format: int32
                  code:
                    type: integer
                    format: int32
                  message:
                    type: string
                  name:
                    type: string
      operationId: postOauthAuthenticate
      x-operation-id-source: derived
  /oauth/userinfo:
    servers:
    - url: https://api.harver.com/
      description: Production Server
    post:
      summary: Get identity claims for a user
      description: Validates an access token and returns the associated identity claims (subject, issued-at, expiry, and client identifier). The `client_id` is always extracted from the token itself and is never accepted as request input.
      tags:
      - OAuth
      requestBody:
        description: The access token to introspect
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              required:
              - token
              properties:
                token:
                  description: Access token previously issued to the client
                  type: string
                  example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
      responses:
        '200':
          description: Valid token — identity claims returned
          content:
            application/json:
              schema:
                type: object
                required:
                - sub
                - exp
                - iat
                - client_id
                properties:
                  sub:
                    type: string
                    description: User identifier
                    example: 5a8d3f2e1b4c7a9d0e6f8b12
                  exp:
                    type: string
                    format: date-time
                    description: Expiry timestamp (ISO 8601)
                    example: '2026-05-15T08:45:10.393Z'
                  iat:
                    type: string
                    format: date-time
                    description: Issued-at timestamp (ISO 8601)
                    example: '2026-05-15T07:45:10.000Z'
                  client_id:
                    type: string
                    description: Client identifier extracted from the token
                    example: my-client-id
        '400':
          description: Malformed request — missing or invalid body
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    example: invalid_request
                  error_description:
                    type: string
                    example: token is required
        '401':
          description: Invalid or expired token
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    example: invalid_token
                  error_description:
                    type: string
                    example: token expired
      operationId: postOauthUserinfo
      x-operation-id-source: derived