OneLogin OAuth API

OAuth 2.0 token generation and revocation

OpenAPI Specification

onelogin-oauth-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: OneLogin Apps OAuth API
  description: OneLogin REST API for identity and access management. Provides programmatic access to users, roles, apps, MFA, branding, connectors, reports, SAML assertions, smart hooks, and Vigilance AI. Authentication is handled via OAuth 2.0 bearer tokens.
  version: '1.0'
  contact:
    name: OneLogin Developers
    url: https://developers.onelogin.com
  license:
    name: OneLogin Terms of Service
    url: https://www.onelogin.com/legal/terms
servers:
- url: https://{subdomain}.onelogin.com
  description: OneLogin tenant subdomain
  variables:
    subdomain:
      default: api
      description: Your OneLogin subdomain
security:
- bearerAuth: []
tags:
- name: OAuth
  description: OAuth 2.0 token generation and revocation
paths:
  /auth/oauth2/v2/token:
    post:
      tags:
      - OAuth
      summary: Generate access token
      description: Generate an OAuth 2.0 bearer token using client credentials.
      operationId: generateToken
      security: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                grant_type:
                  type: string
                  example: client_credentials
      responses:
        '200':
          description: Access token returned
          content:
            application/json:
              schema:
                type: object
                properties:
                  access_token:
                    type: string
                  token_type:
                    type: string
                  expires_in:
                    type: integer
  /auth/oauth2/revoke:
    post:
      tags:
      - OAuth
      summary: Revoke access token
      operationId: revokeToken
      responses:
        '200':
          description: Token revoked
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT