Mojang Authentication API

Exchange Xbox Live tokens for Minecraft access tokens

Operations 1

POST /authentication/login_with_xbox Login With Xbox #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/mojang-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

mojang-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Minecraft Services Authentication API
  description: Microsoft-managed Minecraft Services API (api.minecraftservices.com). Covers authenticated player profile management, name change, skin and cape management, player attributes (chat, friends, profanity filter), privacy blocklist, friends graph, presence reporting, signature keypair issuance, public-key publication for chat signature verification, and player entitlement / ownership checks. Most endpoints require a Minecraft Bearer access token obtained via the Xbox Live -> XSTS -> Minecraft authentication chain.
  version: 1.0.0
  contact:
    name: Mojang Studios
    url: https://www.minecraft.net
  license:
    name: Mojang Brand and Asset Usage Guidelines
    url: https://www.minecraft.net/en-us/usage-guidelines
  x-generated-from: documentation
  x-last-validated: '2026-05-30'
servers:
- url: https://api.minecraftservices.com
  description: Microsoft / Minecraft Services API (production)
security: []
tags:
- name: Authentication
  description: Exchange Xbox Live tokens for Minecraft access tokens
paths:
  /authentication/login_with_xbox:
    post:
      operationId: loginWithXbox
      summary: Login With Xbox
      description: Exchange an XSTS identity token for a Minecraft Bearer access token. First step after completing the Xbox Live authentication chain.
      tags:
      - Authentication
      requestBody:
        required: true
        description: XSTS identity token wrapped in Mojang's expected envelope.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/XboxLoginRequest'
      responses:
        '200':
          description: Minecraft access token issued.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MinecraftAccessToken'
        '401':
          description: Identity token rejected.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
components:
  schemas:
    Error:
      type: object
      description: Standard Minecraft Services error envelope.
      properties:
        path:
          type: string
          description: Request path that produced the error.
          example: /minecraft/profile/lookup/name/zzzzzzzzzzzzzz
        errorType:
          type: string
          description: Mojang error class.
          example: NOT_FOUND
        error:
          type: string
          description: Short error name.
          example: NOT_FOUND
        errorMessage:
          type: string
          description: Human-readable description.
          example: Couldn't find any profile with name zzzzzzzzzzzzzz
        developerMessage:
          type: string
          description: Optional developer-facing message.
          example: Couldn't find any profile with name zzzzzzzzzzzzzz
    MinecraftAccessToken:
      type: object
      description: Successful response from /authentication/login_with_xbox.
      required:
      - access_token
      properties:
        username:
          type: string
          description: Internal Mojang account UUID (different from the player UUID).
          example: 0c11b18a48e94c8d8d8c8f2b3a4e1234
        roles:
          type: array
          description: Account roles array (typically empty for player accounts).
          items:
            type: string
          example: []
        access_token:
          type: string
          description: Minecraft Bearer access token.
          example: eyJraWQiOiJhYmMxMjMi...
        token_type:
          type: string
          description: Token type (always `Bearer`).
          example: Bearer
        expires_in:
          type: integer
          description: Token lifetime in seconds.
          example: 86400
    XboxLoginRequest:
      type: object
      description: Body for /authentication/login_with_xbox.
      required:
      - identityToken
      properties:
        identityToken:
          type: string
          description: XSTS identity token formatted as `XBL3.0 x={userhash};{token}`.
          example: XBL3.0 x=2535465465465465;eyJhbGciOiJSUzI1NiIs...
        ensureLegacyEnabled:
          type: boolean
          description: When true, ensures legacy Mojang accounts can also log in.
          example: true
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Minecraft access token issued by /authentication/login_with_xbox. Used as `Authorization: Bearer {token}`.'