Morningstar Authentication API

OAuth 2.0 token issuance for all Morningstar APIs - POST /token/oauth with Basic credentials returns a bearer token valid for 60 minutes, usable against the regional Americas, EMEA, and APAC API bases.

Operations 1

POST /token/oauth Generate a JSON Web Token (JWT) #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/morningstar-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

morningstar-token-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Authentication Token API
  x-changelog:
  - date: '2026-05-14'
    changes:
    - Corrected error in EMEA server URL. Updated "eu" to "emea".
  description: API for authentication and token retrieval.
  version: 1.0.0
servers:
- url: https://www.us-api.morningstar.com
  description: Americas Production
- url: https://www.apac-api.morningstar.com
  description: APAC Production
- url: https://www.emea-api.morningstar.com
  description: EMEA Production
tags:
- name: Token
paths:
  /token/oauth:
    post:
      summary: Generate a JSON Web Token (JWT)
      description: 'Authenticates a client using HTTP Basic Auth and returns a signed JWT

        bearer token for use in subsequent API requests.


        Pass your credentials as a Base64-encoded `username:password` string in

        the `Authorization` header. The returned `access_token` should be included

        as a `Bearer` token in the `Authorization` header of all authenticated requests.'
      operationId: createToken
      tags:
      - Token
      security:
      - basicAuth: []
      responses:
        '200':
          $ref: '#/components/responses/ResponseToken'
        '401':
          $ref: '#/components/responses/ErrorResponse401'
components:
  examples:
    ResponseTokenExample1:
      summary: Output Authorization Token
      value:
        access_token: Rhci5jb20vaW50ZXJuYWxfY29tcGFueV9pZCI6IkNsaWVudDAiLCJodHRwczovL21vcm5pbmdzdGFyLmNvbS9kYXRhX3JvbGUiOlsiU2VhcmNoLkFDSURfU2VydmljZSJdLCJodHRwczovL21vcm5pbmdzdGFyLmNvbS9jb25maWdfaWQiOiJnbG9iYWxfYWRtaW5fYXBpcy4wMDFkMDAwMDAweDU5YjcuMjA2OTg0MzZfd2twbGMxaDciLCJodHRwczovL21vcm5pbmdzdGFyLmNvbS9tc3Rhcl9pZCI6IkZFMTUzOEM4LTg0RDMtNDlCRC05MzNELTdGQkEyOERGODAzMyIsImh0dHBzOi8vbW9ybmluZ3N0YXIuY29tL2VtYWlsX3ZlcmlmaWVkIjpmYWxzZSwiaHR0cHM6Ly9tb3JuaW5nc3Rhci5jb20vcGFzc3dvcmRDaGFuZ2VSZXF1aXJlZCI6ZmFsc2UsImh0dHBzOi8vbW9ybmluZ3N0YXIuY29tL3VpbV9yb2xlcyI6IkVBTVMsSU5WRVNUTUVOVEFQSV9JTlRFUk5BTF9TRVJWSUNFX0FDQ09VTlQiLCJpc3MiOiJodHRwczovL2xvZ2luLXByb2QubW9ybmluZ3N0YXIuY29tLyIsInN1YiI6ImF1dGgwfEZFMTUzOEM4LTg0RDMtNDlCRC05MzNELTdGQkEyOERGODAzMyIsImF1ZCI6WyJodHRwczovL2F1dGgwLWF3c3By
        expires_in: 3599
        token_type: Bearer
    ErrorResponseExample1:
      summary: '401: Unauthorized'
      value:
        error_message: Incorrect username or password
  responses:
    ResponseToken:
      description: '200: OK'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/OutputToken'
          examples:
            ResponseTokenExample1:
              $ref: '#/components/examples/ResponseTokenExample1'
    ErrorResponse401:
      description: '401: Unauthorized'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            ErrorResponseExample1:
              $ref: '#/components/examples/ErrorResponseExample1'
  schemas:
    ErrorResponse:
      type: object
      description: A response body returned when an error occurs.
      required:
      - error_message
      properties:
        error_message:
          type: string
          description: A human-readable description of the error.
          examples:
          - Incorrect username or password
    OutputToken:
      type: object
      description: A successful authentication response containing a JWT bearer token.
      required:
      - access_token
      - expires_in
      - token_type
      properties:
        access_token:
          type: string
          description: The signed JWT to use as a `Bearer` token in subsequent authenticated requests.
          examples:
          - eyJhbGciOiJ example
        expires_in:
          type: integer
          description: The number of seconds until the token expires. After expiry, request a new token.
          examples:
          - 3599
        token_type:
          type: string
          description: The token type. Always `Bearer`.
          examples:
          - Bearer
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: Base64-encoded `username:password` passed in the `Authorization` header.