Harver OAUTH API
The oauth API from Harver — 3 operation(s) for oauth.
The oauth API from Harver — 3 operation(s) for oauth.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/harver-oauth-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
version: 1.37.0
title: Harver Public OAuth API
description: Public API of the Harver Platform available only for the Customers of Harver.
contact:
name: Harver Support Team
email: support@harver.com
url: https://support.harver.com
servers:
- url: https://api.harver.com/api/v1.0/
description: Production Server
tags:
- name: OAuth
paths:
/oauth/token:
servers:
- url: https://api.harver.com/
description: Production Server
post:
summary: Start an authorized session
description: 'Content-Type should be set to **application/x-www-form-urlencoded**
## Obtaining Tokens
To obtain API tokens for any of your client applications, perform a POST operation to the `/oauth/token` endpoint with a payload in the following format
## Using client_credentials
This type of authorization is used when applications require access to access their own resources, and is not done on behalf of a user. For instance, an Applicant Tracking System checking whether there are new applicants that have completed their application.
## Using an Access Token
Once you have retrieved an Access Token, it can be used until the token expires or is revoked. To use it, send this token in the `Authorization` header when making requests to protected resources.
Authorization: Bearer
#### Example usage:
curl -X GET \
''https://api.harver.com/api/v1.0/accounts'' \
-H ''Authorization: Bearer eyJhbGciOiJIXzI1NiIsInR5cCI6IkpXVCJ9.eyJkYXRhIjp7InVzZXIiOnsiaWQiOiI1OWVkZDZhNvU4YzNlNDI3MDZjOWY3NjgifX0sImlhdCI6MTUzMzEzNDk5Mn0.otr7V1XMzF78LrB3oLRKUvTCxLqYM1CqKKp7UFDcPK8'''
tags:
- OAuth
requestBody:
description: Client ID, Client Secret, Grant Type that should be sent in the request body
required: true
content:
application/x-www-form-urlencoded:
schema:
type: object
additionalProperties: false
required:
- client_id
- client_secret
- grant_type
properties:
client_id:
description: Your Client ID, as provided by Harver
type: string
client_secret:
description: Your Client Secret, as provided by Harver
type: string
grant_type:
description: Must be set to client_credentials
type: string
enum:
- client_credentials
responses:
'200':
description: A generated session
content:
application/json:
schema:
required:
- accessToken
- accessTokenExpiresAt
- user
- userProfile
- client
properties:
user:
required:
- id
properties:
id:
type: string
userProfile:
type: string
accessToken:
type: string
accessTokenExpiresAt:
type: string
format: date-time
client:
required:
- secret
- userId
- id
- roles
- redirectUris
- grants
properties:
secret:
type: string
userId:
type: string
roles:
type: array
items:
type: string
redirectUris:
type: array
items:
type: string
grants:
type: array
items:
type: string
enum:
- password
- client_credentials
id:
type: string
'400':
description: Invalid password or credentials
content:
application/json:
schema:
properties:
statusCode:
type: integer
format: int32
status:
type: integer
format: int32
code:
type: integer
format: int32
message:
type: string
name:
type: string
operationId: postOauthToken
x-operation-id-source: derived
/oauth/authenticate:
servers:
- url: https://api.harver.com/
description: Production Server
post:
summary: Validate auth token
description: '## Validating a Token
To validate a token, perform a POST operation to the `/oauth/authenticate` endpoint with authorization header `Bearer `
## Note: This endpoint is not recommended for public access / not supported
#### Example usage:
curl -X POST \
''https://api.harver.com/auth/authenticate'' \
-H ''Authorization: Bearer eyJhbGciOiJIXzI1NiIsInR5cCI6IkpXVCJ9.eyJkYXRhIjp7InVzZXIiOnsiaWQiOiI1OWVkZDZhNvU4YzNlNDI3MDZjOWY3NjgifX0sImlhdCI6MTUzMzEzNDk5Mn0.otr7V1XMzF78LrB3oLRKUvTCxLqYM1CqKKp7UFDcPK8'''
tags:
- OAuth
responses:
'204':
description: No content
'400':
description: Invalid token
content:
application/json:
schema:
properties:
statusCode:
type: integer
format: int32
status:
type: integer
format: int32
code:
type: integer
format: int32
message:
type: string
name:
type: string
operationId: postOauthAuthenticate
x-operation-id-source: derived
/oauth/userinfo:
servers:
- url: https://api.harver.com/
description: Production Server
post:
summary: Get identity claims for a user
description: Validates an access token and returns the associated identity claims (subject, issued-at, expiry, and client identifier). The `client_id` is always extracted from the token itself and is never accepted as request input.
tags:
- OAuth
requestBody:
description: The access token to introspect
required: true
content:
application/json:
schema:
type: object
additionalProperties: false
required:
- token
properties:
token:
description: Access token previously issued to the client
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
responses:
'200':
description: Valid token — identity claims returned
content:
application/json:
schema:
type: object
required:
- sub
- exp
- iat
- client_id
properties:
sub:
type: string
description: User identifier
example: 5a8d3f2e1b4c7a9d0e6f8b12
exp:
type: string
format: date-time
description: Expiry timestamp (ISO 8601)
example: '2026-05-15T08:45:10.393Z'
iat:
type: string
format: date-time
description: Issued-at timestamp (ISO 8601)
example: '2026-05-15T07:45:10.000Z'
client_id:
type: string
description: Client identifier extracted from the token
example: my-client-id
'400':
description: Malformed request — missing or invalid body
content:
application/json:
schema:
type: object
properties:
error:
type: string
example: invalid_request
error_description:
type: string
example: token is required
'401':
description: Invalid or expired token
content:
application/json:
schema:
type: object
properties:
error:
type: string
example: invalid_token
error_description:
type: string
example: token expired
operationId: postOauthUserinfo
x-operation-id-source: derived