Infisical JWT Auth API

The JWT Auth API from Infisical — 2 operation(s) for jwt auth.

Operations 5

POST /api/v1/auth/jwt-auth/login #
POST /api/v1/auth/jwt-auth/identities/{identityId} #
PATCH /api/v1/auth/jwt-auth/identities/{identityId} #
GET /api/v1/auth/jwt-auth/identities/{identityId} #
DELETE /api/v1/auth/jwt-auth/identities/{identityId} #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/infisical-jwt-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

infisical-jwt-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Infisical Admin JWT Auth API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
- url: https://us.infisical.com
  description: Production server (US)
- url: https://eu.infisical.com
  description: Production server (EU)
- url: http://localhost:8080
  description: Local server
tags:
- name: JWT Auth
paths:
  /api/v1/auth/jwt-auth/login:
    post:
      operationId: loginWithJwtAuth
      tags:
      - JWT Auth
      description: Login with JWT Auth for machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                identityId:
                  type: string
                  description: The ID of the machine identity to login.
                jwt:
                  type: string
                organizationSlug:
                  type: string
                  minLength: 1
                  maxLength: 64
                  description: When set, this will scope the login session to the specified organization the machine identity has access to. If omitted, the session defaults to the organization where the machine identity was created in.
              required:
              - identityId
              - jwt
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  accessToken:
                    type: string
                  expiresIn:
                    type: number
                  accessTokenMaxTTL:
                    type: number
                  tokenType:
                    type: string
                    enum:
                    - Bearer
                required:
                - accessToken
                - expiresIn
                - accessTokenMaxTTL
                - tokenType
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
  /api/v1/auth/jwt-auth/identities/{identityId}:
    post:
      operationId: attachJwtAuth
      tags:
      - JWT Auth
      description: Attach JWT Auth configuration onto machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              anyOf:
              - type: object
                properties:
                  configurationType:
                    type: string
                    enum:
                    - jwks
                    description: 'The configuration for validating JWTs. Must be one of: ''jwks'', ''static'''
                  jwksUrl:
                    type: string
                    format: uri
                    description: The URL of the JWKS endpoint. Required if configurationType is 'jwks'. This endpoint must serve JSON Web Key Sets (JWKS) containing the public keys used to verify JWT signatures.
                  jwksCaCert:
                    type: string
                    default: ''
                    description: The PEM-encoded CA certificate for validating the TLS connection to the JWKS endpoint.
                  publicKeys:
                    type: array
                    items:
                      type: string
                    default: []
                    description: A list of PEM-encoded public keys used to verify JWT signatures. Required if configurationType is 'static'. Each key must be in RSA or ECDSA format and properly PEM-encoded with BEGIN/END markers.
                  boundIssuer:
                    type: string
                    default: ''
                    description: The unique identifier of the JWT provider.
                  boundAudiences:
                    type: string
                    default: ''
                    description: The list of intended recipients.
                  boundClaims:
                    type: object
                    additionalProperties:
                      type: string
                    description: The attributes that should be present in the JWT for it to be valid.
                  boundSubject:
                    type: string
                    default: ''
                    description: The expected principal that is the subject of the JWT.
                  accessTokenTrustedIps:
                    type: array
                    items:
                      type: object
                      properties:
                        ipAddress:
                          type: string
                      required:
                      - ipAddress
                      additionalProperties: false
                    minItems: 1
                    default:
                    - ipAddress: 0.0.0.0/0
                    - ipAddress: ::/0
                    description: The IPs or CIDR ranges that access tokens can be used from.
                  accessTokenTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The lifetime for an access token in seconds.
                  accessTokenMaxTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The maximum lifetime for an access token in seconds.
                  accessTokenNumUsesLimit:
                    type: integer
                    minimum: 0
                    default: 0
                    description: The maximum number of times that an access token can be used.
                required:
                - configurationType
                - jwksUrl
                - boundClaims
                additionalProperties: false
              - type: object
                properties:
                  configurationType:
                    type: string
                    enum:
                    - static
                    description: 'The configuration for validating JWTs. Must be one of: ''jwks'', ''static'''
                  jwksUrl:
                    type: string
                    default: ''
                    description: The URL of the JWKS endpoint. Required if configurationType is 'jwks'. This endpoint must serve JSON Web Key Sets (JWKS) containing the public keys used to verify JWT signatures.
                  jwksCaCert:
                    type: string
                    default: ''
                    description: The PEM-encoded CA certificate for validating the TLS connection to the JWKS endpoint.
                  publicKeys:
                    type: array
                    items:
                      type: string
                      minLength: 1
                    minItems: 1
                    description: A list of PEM-encoded public keys used to verify JWT signatures. Required if configurationType is 'static'. Each key must be in RSA or ECDSA format and properly PEM-encoded with BEGIN/END markers.
                  boundIssuer:
                    type: string
                    default: ''
                    description: The unique identifier of the JWT provider.
                  boundAudiences:
                    type: string
                    default: ''
                    description: The list of intended recipients.
                  boundClaims:
                    type: object
                    additionalProperties:
                      type: string
                    description: The attributes that should be present in the JWT for it to be valid.
                  boundSubject:
                    type: string
                    default: ''
                    description: The expected principal that is the subject of the JWT.
                  accessTokenTrustedIps:
                    type: array
                    items:
                      type: object
                      properties:
                        ipAddress:
                          type: string
                      required:
                      - ipAddress
                      additionalProperties: false
                    minItems: 1
                    default:
                    - ipAddress: 0.0.0.0/0
                    - ipAddress: ::/0
                    description: The IPs or CIDR ranges that access tokens can be used from.
                  accessTokenTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The lifetime for an access token in seconds.
                  accessTokenMaxTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The maximum lifetime for an access token in seconds.
                  accessTokenNumUsesLimit:
                    type: integer
                    minimum: 0
                    default: 0
                    description: The maximum number of times that an access token can be used.
                required:
                - configurationType
                - publicKeys
                - boundClaims
                additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to attach the configuration onto.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identityJwtAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      identityId:
                        type: string
                        format: uuid
                      configurationType:
                        type: string
                      jwksUrl:
                        type: string
                      boundIssuer:
                        type: string
                      boundAudiences:
                        type: string
                      boundClaims: {}
                      boundSubject:
                        type: string
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      accessTokenPeriod:
                        type: number
                        default: 0
                      jwksCaCert:
                        type: string
                      publicKeys:
                        type: array
                        items:
                          type: string
                    required:
                    - id
                    - identityId
                    - configurationType
                    - jwksUrl
                    - boundIssuer
                    - boundAudiences
                    - boundSubject
                    - createdAt
                    - updatedAt
                    - jwksCaCert
                    - publicKeys
                    additionalProperties: false
                required:
                - identityJwtAuth
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    patch:
      operationId: updateJwtAuth
      tags:
      - JWT Auth
      description: Update JWT Auth configuration on machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              anyOf:
              - type: object
                properties:
                  configurationType:
                    type: string
                    enum:
                    - jwks
                    description: 'The configuration for validating JWTs. Must be one of: ''jwks'', ''static'''
                  jwksUrl:
                    type: string
                    format: uri
                    description: The URL of the JWKS endpoint. Required if configurationType is 'jwks'. This endpoint must serve JSON Web Key Sets (JWKS) containing the public keys used to verify JWT signatures.
                  jwksCaCert:
                    type: string
                    default: ''
                    description: The PEM-encoded CA certificate for validating the TLS connection to the JWKS endpoint.
                  publicKeys:
                    type: array
                    items:
                      type: string
                    default: []
                    description: A list of PEM-encoded public keys used to verify JWT signatures. Required if configurationType is 'static'. Each key must be in RSA or ECDSA format and properly PEM-encoded with BEGIN/END markers.
                  boundIssuer:
                    type: string
                    default: ''
                    description: The new unique identifier of the JWT provider.
                  boundAudiences:
                    type: string
                    default: ''
                    description: The new list of intended recipients.
                  boundClaims:
                    type: object
                    additionalProperties:
                      type: string
                    description: The new attributes that should be present in the JWT for it to be valid.
                  boundSubject:
                    type: string
                    default: ''
                    description: The new expected principal that is the subject of the JWT.
                  accessTokenTrustedIps:
                    type: array
                    items:
                      type: object
                      properties:
                        ipAddress:
                          type: string
                      required:
                      - ipAddress
                      additionalProperties: false
                    minItems: 1
                    default:
                    - ipAddress: 0.0.0.0/0
                    - ipAddress: ::/0
                    description: The new IPs or CIDR ranges that access tokens can be used from.
                  accessTokenTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The new lifetime for an access token in seconds.
                  accessTokenMaxTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The new maximum lifetime for an access token in seconds.
                  accessTokenNumUsesLimit:
                    type: integer
                    minimum: 0
                    default: 0
                    description: The new maximum number of times that an access token can be used.
                required:
                - configurationType
                - jwksUrl
                additionalProperties: false
              - type: object
                properties:
                  configurationType:
                    type: string
                    enum:
                    - static
                    description: 'The configuration for validating JWTs. Must be one of: ''jwks'', ''static'''
                  jwksUrl:
                    type: string
                    default: ''
                    description: The URL of the JWKS endpoint. Required if configurationType is 'jwks'. This endpoint must serve JSON Web Key Sets (JWKS) containing the public keys used to verify JWT signatures.
                  jwksCaCert:
                    type: string
                    default: ''
                    description: The PEM-encoded CA certificate for validating the TLS connection to the JWKS endpoint.
                  publicKeys:
                    type: array
                    items:
                      type: string
                      minLength: 1
                    minItems: 1
                    description: A list of PEM-encoded public keys used to verify JWT signatures. Required if configurationType is 'static'. Each key must be in RSA or ECDSA format and properly PEM-encoded with BEGIN/END markers.
                  boundIssuer:
                    type: string
                    default: ''
                    description: The new unique identifier of the JWT provider.
                  boundAudiences:
                    type: string
                    default: ''
                    description: The new list of intended recipients.
                  boundClaims:
                    type: object
                    additionalProperties:
                      type: string
                    description: The new attributes that should be present in the JWT for it to be valid.
                  boundSubject:
                    type: string
                    default: ''
                    description: The new expected principal that is the subject of the JWT.
                  accessTokenTrustedIps:
                    type: array
                    items:
                      type: object
                      properties:
                        ipAddress:
                          type: string
                      required:
                      - ipAddress
                      additionalProperties: false
                    minItems: 1
                    default:
                    - ipAddress: 0.0.0.0/0
                    - ipAddress: ::/0
                    description: The new IPs or CIDR ranges that access tokens can be used from.
                  accessTokenTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The new lifetime for an access token in seconds.
                  accessTokenMaxTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The new maximum lifetime for an access token in seconds.
                  accessTokenNumUsesLimit:
                    type: integer
                    minimum: 0
                    default: 0
                    description: The new maximum number of times that an access token can be used.
                required:
                - configurationType
                - publicKeys
                additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to update the auth method for.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identityJwtAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      identityId:
                        type: string
                        format: uuid
                      configurationType:
                        type: string
                      jwksUrl:
                        type: string
                      boundIssuer:
                        type: string
                      boundAudiences:
                        type: string
                      boundClaims: {}
                      boundSubject:
                        type: string
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      accessTokenPeriod:
                        type: number
                        default: 0
                      jwksCaCert:
                        type: string
                      publicKeys:
                        type: array
                        items:
                          type: string
                    required:
                    - id
                    - identityId
                    - configurationType
                    - jwksUrl
                    - boundIssuer
                    - boundAudiences
                    - boundSubject
                    - createdAt
                    - updatedAt
                    - jwksCaCert
                    - publicKeys
                    additionalProperties: false
                required:
                - identityJwtAuth
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: str

# --- truncated at 32 KB (45 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/infisical/refs/heads/main/openapi/infisical-jwt-auth-api-openapi.yml