PassiveLogic Authentication API

Routes related to user auth

Operations 72

GET /api/v0.20/auth/email/change/verify Verifies and updates new user email #
GET /api/v0.19/auth/email/change/verify Verifies and updates new user email #
GET /api/auth/email/change/verify Verifies and updates new user email #
POST /api/auth/password/change Changes a user's password for an already authenticated user. #
GET /api/auth/password/change Redirects the user to the change password flow in the external auth provider (Keycloak). #
POST /api/v0.19/auth/password/reset Initiates a password reset. #
GET /api/v0.20/auth/login Logs in a user #
GET /api/v0.19/auth/login Logs in a user #
DELETE /api/v0.20/auth/api-key Removes a given API key for the user #
POST /api/auth/register Registers a new user #
GET /api/auth/login Logs in a user #
POST /api/v0.20/auth/logout Logs out a user #
GET /api/v0.19/auth/zendesk Logs a user in to Zendesk using their PL Account #
GET /api/v0.19/auth/verify Redirects user to login #
GET /api/auth/keys Returns the public keys used to sign PassiveLogic JSON web tokens. #
POST /api/auth/password/reset Initiates a password reset. #
GET /api/v0.20/auth/whoami Returns information about the currently logged in user. #
GET /api/v0.20/auth/verify Redirects user to login #
POST /api/v0.19/auth/register Registers a new user #
GET /api/auth/api-key/generate Generates an API key for the current user #
GET /api/v0.20/auth/keys Returns the public keys used to sign PassiveLogic JSON web tokens. #
DELETE /api/v0.19/auth/api-key Removes a given API key for the user #
POST /api/auth/password/reset/change Changes a user's password from the password reset flow. #
GET /api/auth/offline
POST /api/auth/register/initiate Sends an email to begin email verification and registration. #
GET /api/auth/verify Redirects user to login #
DELETE /api/auth/api-key/remove Removes a given API key for the user. This route has been deprecated in favor of: DELETE /api/auth/api-key. #
POST /api/auth/api-key/remove Removes a given API key for the user. This route has been deprecated in favor of: DELETE /api/auth/api-key. #
POST /api/v0.19/auth/logout Logs out a user #
POST /api/v0.20/auth/register Registers a new user #
GET /api/v0.19/auth/offline
POST /api/v0.20/auth/password/change Changes a user's password for an already authenticated user. #
GET /api/v0.20/auth/password/change Redirects the user to the change password flow in the external auth provider (Keycloak). #
DELETE /api/auth/api-key Removes a given API key for the user #
GET /api/v0.19/auth/keys Returns the public keys used to sign PassiveLogic JSON web tokens. #
POST /api/v0.20/auth/password/reset Initiates a password reset. #
POST /api/auth/email/change Initiates an email change for the current user. #
GET /api/auth/profile/change Redirects the user the change profile flow in the external auth provider (Keycloak). #
DELETE /api/v0.19/auth/api-key/remove Removes a given API key for the user. This route has been deprecated in favor of: DELETE /api/v0.19/auth/api-key. #
POST /api/v0.19/auth/api-key/remove Removes a given API key for the user. This route has been deprecated in favor of: DELETE /api/v0.19/auth/api-key. #
GET /api/v0.20/auth/profile/change Redirects the user the change profile flow in the external auth provider (Keycloak). #
POST /api/v0.20/auth/password/reset/change Changes a user's password from the password reset flow. #
GET /api/v0.20/auth/zendesk Logs a user in to Zendesk using their PL Account #
POST /api/v0.19/auth/password/reset/change Changes a user's password from the password reset flow. #
POST /api/v0.20/auth/email/change Initiates an email change for the current user. #
POST /api/v0.20/auth/kc/{user} Validates a user's password #
GET /api/v0.20/auth/kc/{user} Retrieves user information for Keycloak #
GET /api/auth/whoami Returns information about the currently logged in user. #
POST /api/auth/kc/{user} Validates a user's password #
GET /api/auth/kc/{user} Retrieves user information for Keycloak #
POST /api/v0.19/auth/password/change Changes a user's password for an already authenticated user. #
GET /api/v0.19/auth/password/change Redirects the user to the change password flow in the external auth provider (Keycloak). #
DELETE /api/v0.20/auth/api-key/remove Removes a given API key for the user. This route has been deprecated in favor of: DELETE /api/v0.20/auth/api-key. #
POST /api/v0.20/auth/api-key/remove Removes a given API key for the user. This route has been deprecated in favor of: DELETE /api/v0.20/auth/api-key. #
GET /api/v0.20/auth/api-key/generate Generates an API key for the current user #
GET /api/auth/zendesk Logs a user in to Zendesk using their PL Account #
GET /api/v0.19/auth/profile/change Redirects the user the change profile flow in the external auth provider (Keycloak). #
GET /api/v0.19/auth/api-key/generate Generates an API key for the current user #
POST /api/auth/logout Logs out a user #
POST /api/v0.19/auth/kc/{user} Validates a user's password #
GET /api/v0.19/auth/kc/{user} Retrieves user information for Keycloak #
GET /api/v0.19/auth/whoami Returns information about the currently logged in user. #
POST /api/v0.19/auth/register/initiate Sends an email to begin email verification and registration. #
POST /api/v0.19/auth/email/change Initiates an email change for the current user. #
POST /api/v0.20/auth/register/initiate Sends an email to begin email verification and registration. #
GET /api/v0.20/auth/offline

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/passivelogic-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

passivelogic-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Passivelogic Authentication API
  version: 0.0.0
  description: 'Operations tagged Authentication across 2 of this provider''s published API definitions: passivelogic-authentication-api-openapi.yml, passivelogic-rest-api-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://passivelogic.com/api/
  description: Base URL declared by the provider in apis.yml (roadmap#122).
tags:
- description: Routes related to user auth
  name: Authentication
paths:
  /api/v0.20/auth/email/change/verify:
    get:
      deprecated: true
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdatedUserEmail'
            examples:
              UpdatedUserEmail:
                $ref: '#/components/examples/UpdatedUserEmail'
        required: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Verifies and updates new user email
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Verifies the new email is valid. Updates the user email with the newly validated one.


        Token authentication required. Provided by /api/v0.20/auth/email/change.'
      responses:
        '200':
          content:
            application/json:
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
          description: OK
      operationId: getApiV0.20AuthEmailChangeVerify
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/magic-link-generate:
    post:
      deprecated: true
      requestBody:
        content:
          application/json:
            examples:
              UserRegistrationInitiation:
                $ref: '#/components/examples/UserRegistrationInitiation'
            schema:
              $ref: '#/components/schemas/UserRegistrationInitiation'
        required: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Generates a Magic Link to be used to login.
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Generates magic link containing `?token=<signed JWT with user email contained>` and sends it in an email to the user.

        This is the secure mode and MUST be used in production.

        This will not return a link to the client.


        If User does not exist in Database, will throw 400 bad request. If user exists, will return 200 ok.

        These links can then be used to login from GET magic-link-login.'
      operationId: postApiAuthMagic-link-generate
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MagicLinkResponse'
          description: OK
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.19/auth/email/change/verify:
    get:
      deprecated: true
      requestBody:
        required: true
        content:
          application/json:
            examples:
              UpdatedUserEmail:
                $ref: '#/components/examples/UpdatedUserEmail'
            schema:
              $ref: '#/components/schemas/UpdatedUserEmail'
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Verifies and updates new user email
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Verifies the new email is valid. Updates the user email with the newly validated one.


        Token authentication required. Provided by /api/v0.19/auth/email/change.'
      tags:
      - Authentication
      operationId: getApiV0.19AuthEmailChangeVerify
      responses:
        '200':
          content:
            application/json:
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
          description: OK
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/email/change/verify:
    get:
      deprecated: true
      requestBody:
        required: true
        content:
          application/json:
            examples:
              UpdatedUserEmail:
                $ref: '#/components/examples/UpdatedUserEmail'
            schema:
              $ref: '#/components/schemas/UpdatedUserEmail'
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Verifies and updates new user email
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Verifies the new email is valid. Updates the user email with the newly validated one.


        Token authentication required. Provided by /api/auth/email/change.'
      operationId: getApiAuthEmailChangeVerify
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/password/change:
    post:
      deprecated: true
      requestBody:
        content:
          application/json:
            examples:
              ChangeUserPassword:
                $ref: '#/components/examples/ChangeUserPassword'
            schema:
              $ref: '#/components/schemas/ChangeUserPassword'
        required: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Changes a user's password for an already authenticated user.
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Changes an authenticated user''s password to the specified value.'
      operationId: postApiAuthPasswordChange
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
          description: OK
    get:
      tags:
      - Authentication
      operationId: getApiAuthPasswordChange
      description: ''
      summary: Redirects the user to the change password flow in the external auth provider (Keycloak).
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.19/auth/password/reset:
    post:
      deprecated: true
      requestBody:
        required: true
        content:
          application/json:
            examples:
              RequestResetPasswordData:
                $ref: '#/components/examples/RequestResetPasswordData'
            schema:
              $ref: '#/components/schemas/RequestResetPasswordData'
      summary: Initiates a password reset.
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Initiates a password reset for the given user, sending them an email with a password reset link authenticated to their

        account only.'
      operationId: postApiV0.19AuthPasswordReset
      responses:
        '200':
          content:
            application/json:
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
          description: OK
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.20/auth/login:
    get:
      deprecated: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Logs in a user
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Logs in a user. If multi-factor authentication is enabled, returns a multi-factor token that can be used to

        send a multi-factor code to the user. Otherwise, sets auth & refresh tokens as cookies and returns a whoami for the

        logged in user.


        Basic authentication required.'
      operationId: getApiV0.20AuthLogin
      responses:
        '200':
          content:
            application/json:
              examples:
                LoginResponse:
                  $ref: '#/components/examples/LoginResponse'
              schema:
                $ref: '#/components/schemas/LoginResponse'
          description: OK
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.19/auth/login:
    get:
      deprecated: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Logs in a user
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Logs in a user. If multi-factor authentication is enabled, returns a multi-factor token that can be used to

        send a multi-factor code to the user. Otherwise, sets auth & refresh tokens as cookies and returns a whoami for the

        logged in user.


        Basic authentication required.'
      operationId: getApiV0.19AuthLogin
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LoginResponse'
              examples:
                LoginResponse:
                  $ref: '#/components/examples/LoginResponse'
          description: OK
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.20/auth/api-key:
    delete:
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      requestBody:
        content:
          application/json:
            examples:
              RemoveApiKeyRequest:
                $ref: '#/components/examples/RemoveApiKeyRequest'
            schema:
              $ref: '#/components/schemas/RemoveApiKeyRequest'
        required: true
      summary: Removes a given API key for the user
      tags:
      - Authentication
      description: Validates that the given token is linked to the currently authenticated user and removes it if so.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenerateApiKeyResponse'
              examples:
                GenerateApiKeyResponse:
                  $ref: '#/components/examples/GenerateApiKeyResponse'
      operationId: deleteApiV0.20AuthApi-key
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/register:
    post:
      deprecated: true
      requestBody:
        content:
          application/json:
            examples:
              RegisterUserData:
                $ref: '#/components/examples/RegisterUserData'
            schema:
              $ref: '#/components/schemas/RegisterUserData'
        required: true
      summary: Registers a new user
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Creates a new user based on the provided information. Requires jwt obtained via email from

        `/api/auth/register/initiate`. The user status is set to `Active` and immediately logged in.




        Registration token is required when email verification is enforced, as indicated by a failed response to this endpoint'
      operationId: postApiAuthRegister
      responses:
        '200':
          description: OK
          content:
            application/json:
              examples:
                RegisterUserResponse:
                  $ref: '#/components/examples/RegisterUserResponse'
              schema:
                $ref: '#/components/schemas/RegisterUserResponse'
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/login:
    get:
      deprecated: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Logs in a user
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Logs in a user. If multi-factor authentication is enabled, returns a multi-factor token that can be used to

        send a multi-factor code to the user. Otherwise, sets auth & refresh tokens as cookies and returns a whoami for the

        logged in user.


        Basic authentication required.'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LoginResponse'
              examples:
                LoginResponse:
                  $ref: '#/components/examples/LoginResponse'
          description: OK
      operationId: getApiAuthLogin
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.20/auth/logout:
    post:
      description: 'If external auth (Keycloak) is enabled, this initiates the external logout process.


        Otherwise, if a cookie keyed by pl-refresh-token is provided in the logout request, that refresh token is revoked.


        The response sets the auth & refresh cookies to empty values & marks them as expired.

        New tokens must then be generated by the login endpoint.'
      responses:
        '200':
          description: OK
          content:
            application/json:
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      tags:
      - Authentication
      operationId: postApiV0.20AuthLogout
      summary: Logs out a user
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.19/auth/zendesk:
    get:
      description: 'Redirects a user to the PassiveLogic Zendesk portal.

        If they are already authenticated with their PL account when making this request,

        they will be automatically logged in to Zendesk as well. Otherwise they will be redirected to the Zendesk login page.

        A `returnTo` query parameter can be used to support deep linking to, for example, specific support articles.'
      summary: Logs a user in to Zendesk using their PL Account
      operationId: getApiV0.19AuthZendesk
      tags:
      - Authentication
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.19/auth/verify:
    get:
      description: 'Redirects user to `/api/v0.19/auth/login`, passing along the provided valid jwt and email.


        Exists in this form for backward compatibility.'
      parameters:
      - description: User's email to confirm as verified
        required: true
        example: darthvader@galactic-empire.com
        name: email
        schema:
          type: string
        in: query
      operationId: getApiV0.19AuthVerify
      summary: Redirects user to login
      tags:
      - Authentication
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/keys:
    get:
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/JWKS'
      tags:
      - Authentication
      description: 'Returns the public keys used to sign the JSON web tokens so their authenticity can be verified. These are served in the

        standard JSON Web Key format: https://www.rfc-editor.org/rfc/rfc7517'
      summary: Returns the public keys used to sign PassiveLogic JSON web tokens.
      operationId: getApiAuthKeys
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/password/reset:
    post:
      deprecated: true
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RequestResetPasswordData'
            examples:
              RequestResetPasswordData:
                $ref: '#/components/examples/RequestResetPasswordData'
        required: true
      summary: Initiates a password reset.
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Initiates a password reset for the given user, sending them an email with a password reset link authenticated to their

        account only.'
      responses:
        '200':
          description: OK
          content:
            application/json:
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
      operationId: postApiAuthPasswordReset
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.20/auth/whoami:
    get:
      summary: Returns information about the currently logged in user.
      description: Useful to check if a user is authenticated.
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      operationId: getApiV0.20AuthWhoami
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WhoAmIResponse'
              examples:
                WhoAmIResponse:
                  $ref: '#/components/examples/WhoAmIResponse'
      tags:
      - Authentication
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.20/auth/verify:
    get:
      parameters:
      - description: User's email to confirm as verified
        example: darthvader@galactic-empire.com
        required: true
        schema:
          type: string
        name: email
        in: query
      description: 'Redirects user to `/api/v0.20/auth/login`, passing along the provided valid jwt and email.


        Exists in this form for backward compatibility.'
      tags:
      - Authentication
      summary: Redirects user to login
      operationId: getApiV0.20AuthVerify
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/magic-link-login:
    get:
      deprecated: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Logs in a user using Magic Link generated by POST magic-link-generate
      tags:
      - Authentication
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Requires a magic login link containing containing `?token=<signed JWT with user email contained>`.

        This is the secure mode and MUST be used in production.'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
          description: OK
      operationId: getApiAuthMagic-link-login
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.19/auth/register:
    post:
      deprecated: true
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RegisterUserData'
            examples:
              RegisterUserData:
                $ref: '#/components/examples/RegisterUserData'
        required: true
      summary: Registers a new user
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Creates a new user based on the provided information. Requires jwt obtained via email from

        `/api/v0.19/auth/register/initiate`. The user status is set to `Active` and immediately logged in.




        Registration token is required when email verification is enforced, as indicated by a failed response to this endpoint'
      tags:
      - Authentication
      operationId: postApiV0.19AuthRegister
      responses:
        '200':
          description: OK
          content:
            application/json:
              examples:
                RegisterUserResponse:
                  $ref: '#/components/examples/RegisterUserResponse'
              schema:
                $ref: '#/components/schemas/RegisterUserResponse'
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/api-key/generate:
    get:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenerateApiKeyResponse'
              examples:
                GenerateApiKeyResponse:
                  $ref: '#/components/examples/GenerateApiKeyResponse'
          description: OK
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Generates an API key for the current user
      tags:
      - Authentication
      description: 'Generates, stores, and returns a new API key with the default expiration period for the user currently logged in.


        Once created, you can then provide this API key in an

        `Authorization: PL-API-KEY <Key>` header in replacement of an `X-PL-AUTH` header.'
      parameters:
      - schema:
          type:
          - integer
          - 'null'
          format: int64
        example: 2678400
        required: false
        name: expireSeconds
        in: query
        description: Number of seconds until the key expires.
      - schema:
          type:
          - string
          - 'null'
        example: ReadOnlyUser
        required: false
        name: role
        in: query
        description: Role of the new key.
      operationId: getApiAuthApi-keyGenerate
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.20/auth/keys:
    get:
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/JWKS'
      tags:
      - Authentication
      summary: Returns the public keys used to sign PassiveLogic JSON web tokens.
      description: 'Returns the public keys used to sign the JSON web tokens so their authenticity can be verified. These are served in the

        standard JSON Web Key format: https://www.rfc-editor.org/rfc/rfc7517'
      operationId: getApiV0.20AuthKeys
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/v0.19/auth/api-key:
    delete:
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RemoveApiKeyRequest'
            examples:
              RemoveApiKeyRequest:
                $ref: '#/components/examples/RemoveApiKeyRequest'
        required: true
      summary: Removes a given API key for the user
      tags:
      - Authentication
      description: Validates that the given token is linked to the currently authenticated user and removes it if so.
      operationId: deleteApiV0.19AuthApi-key
      responses:
        '200':
          description: OK
          content:
            application/json:
              examples:
                GenerateApiKeyResponse:
                  $ref: '#/components/examples/GenerateApiKeyResponse'
              schema:
                $ref: '#/components/schemas/GenerateApiKeyResponse'
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/password/reset/change:
    post:
      deprecated: true
      requestBody:
        required: true
        content:
          application/json:
            examples:
              ChangePasswordData:
                $ref: '#/components/examples/ChangePasswordData'
            schema:
              $ref: '#/components/schemas/ChangePasswordData'
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: Changes a user's password from the password reset flow.
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Changes a user''s password to the specified value, reached from password reset flow.


        Token authentication required, only using the authentication JWT decoded from the password reset URL sent to a user

        from a reset initiation.'
      tags:
      - Authentication
      operationId: postApiAuthPasswordResetChange
      responses:
        '200':
          content:
            application/json:
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
          description: OK
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/offline:
    get:
      tags:
      - Authentication
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      description: GET /auth/offline
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/register/initiate:
    post:
      deprecated: true
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserRegistrationInitiation'
            examples:
              UserRegistrationInitiation:
                $ref: '#/components/examples/UserRegistrationInitiation'
        required: true
      summary: Sends an email to begin email verification and registration.
      description: 'DEPRECATED: This endpoint is not available when Keycloak authentication is turned on and will be removed in the future.


        Initiates the PassiveLogic registration process by sending an email to the given user. A user is not stored in the system

        at this point in the process - instead this serves as the initial step proving that a uer has access to the email they

        are signing up with.


        Email will contain a link that holds a signed JWT from us. That JWT is later used to validate and complete registration.


        No authentication required.'
      tags:
      - Authentication
      operationId: postApiAuthRegisterInitiate
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericMessageResponse'
              examples:
                GenericMessageResponse:
                  $ref: '#/components/examples/GenericMessageResponse'
          description: OK
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/verify:
    get:
      operationId: getApiAuthVerify
      tags:
      - Authentication
      parameters:
      - name: email
        description: User's email to confirm as verified
        in: query
        required: true
        schema:
          type: string
        example: darthvader@galactic-empire.com
      description: 'Redirects user to `/api/auth/login`, passing along the provided valid jwt and email.


        Exists in this form for backward compatibility.'
      summary: Redirects user to login
    servers:
    - url: https://passivelogic.com/api/
      description: Base URL declared by the provider in apis.yml (roadmap#122).
  /api/auth/api-key/remove:
    delete:
      deprecated: true
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RemoveApiKeyRequest'
            examples:
              RemoveApiKeyRequest:
                $ref: '#/components/examples/RemoveApiKeyRequest'
        required: true
      security:
      - Basic Auth - login: []
      - XSRF header: []
      - DEPRECATED - PL API Key: []
      - PL API Key: []
      summary: 'Removes a given API key for the user. This route has been deprecated in favor of: DELETE /api/auth/api-key.'
      tags:
      - Authentication
      description: Validates that the given token is linked to the currently authenticated user and removes it if so.
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenerateApiKeyResponse'
              examples:
                GenerateApiKeyResponse:
                  $ref: '#/components/examples/GenerateApiKeyResponse'
          description: OK
      operationId: deleteApiAuthApi-keyRemove
    post:
      deprecated: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RemoveApiKeyRequest'
            exam

# --- truncated at 32 KB (91 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/passivelogic/refs/heads/main/openapi/passivelogic-authentication-api-openapi.yml