PipesHub OpenID Connect API

OpenID Connect 1.0 endpoints for identity federation and discovery. **Discovery:** - `/.well-known/openid-configuration` - Authorization server metadata - `/.well-known/oauth-authorization-server` - Authorization server metadata (RFC 8414) - `/.well-known/oauth-protected-resource/mcp` - Protected resource metadata (RFC 9728) - `/.well-known/jwks.json` - Public keys for token verification **UserInfo:** - `/oauth2/userinfo` - Get authenticated user's profile information **Supported Claims:** - `user_id` - User identifier - `email`, `email_verified` - Email information - `name`, `given_name`, `family_name` - Name information

Operations 5

GET /oauth2/userinfo Get authenticated user information #
GET /.well-known/openid-configuration OpenID Connect Discovery #
GET /.well-known/oauth-authorization-server OAuth 2.0 Authorization Server Metadata #
GET /.well-known/jwks.json JSON Web Key Set #
GET /.well-known/oauth-protected-resource/mcp OAuth Protected Resource Metadata #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/pipeshub:pipeshub-openid-connect-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

pipeshub-openid-connect-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Pipeshub OpenID Connect API
  version: 1.0.0
  contact:
    name: API Support
    email: support@pipeshub.com
  description: 'Operations tagged OpenID Connect across 2 of this provider''s published API definitions: pipeshub-openapi.yaml, pipeshub-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: '{instance_url}/api/v1'
  description: Base API URL
  variables:
    instance_url:
      default: https://app.pipeshub.com
      description: Base server URL (without /api/v1)
- url: '{instance_url}'
  description: Root URL (used for MCP endpoints mounted at /mcp)
  variables:
    instance_url:
      default: https://app.pipeshub.com
      description: Base server URL
security:
- bearerAuth: []
- oauth2: []
tags:
- name: OpenID Connect
  description: OpenID Connect 1.0 endpoints for identity federation and discovery.
paths:
  /oauth2/userinfo:
    get:
      tags:
      - OpenID Connect
      summary: Get authenticated user information
      description: 'OpenID Connect UserInfo Endpoint.


        Returns claims about the authenticated user. Requires a valid access token

        with the `openid` scope.


        **Available Claims:**

        - `user_id` - User identifier

        - `name`, `given_name`, `family_name` - Name claims (with `profile` scope)

        - `email`, `email_verified` - Email claims (with `email` scope)


        **Authentication:**

        Pass the access token as a Bearer token: `Authorization: Bearer {access_token}`'
      operationId: oauthUserInfo
      x-pipeshub-sdk: true
      security:
      - bearerAuth: []
      responses:
        '200':
          description: User information
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthUserInfoResponse'
              example:
                user_id: user-id-123
                name: John Doe
                given_name: John
                family_name: Doe
                email: john.doe@example.com
                email_verified: true
        '401':
          description: Invalid or missing access token
        '403':
          description: Token does not have openid scope
    servers:
    - url: '{instance_url}/api/v1'
      description: Base API URL
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL (without /api/v1)
    - url: '{instance_url}'
      description: Root URL (used for MCP endpoints mounted at /mcp)
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL
  /.well-known/openid-configuration:
    get:
      tags:
      - OpenID Connect
      summary: OpenID Connect Discovery
      description: 'OpenID Connect Discovery Endpoint (RFC 8414).


        Returns metadata about the OAuth/OIDC authorization server including

        endpoint URLs, supported features, and capabilities.


        Use Cases:


        - Automatic client configuration


        - Discovering supported features


        - Getting endpoint URLs without hardcoding


        Note: This endpoint does not require authentication.'
      operationId: openidConfiguration
      security: []
      servers:
      - url: /
        description: Root URL (not /api/v1)
      responses:
        '200':
          description: Authorization server metadata
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OpenIDConfiguration'
              example:
                issuer: https://api.pipeshub.com
                authorization_endpoint: https://api.pipeshub.com/oauth2/authorize
                token_endpoint: https://api.pipeshub.com/oauth2/token
                userinfo_endpoint: https://api.pipeshub.com/oauth2/userinfo
                revocation_endpoint: https://api.pipeshub.com/oauth2/revoke
                introspection_endpoint: https://api.pipeshub.com/oauth2/introspect
                jwks_uri: https://api.pipeshub.com/.well-known/jwks.json
                scopes_supported:
                - openid
                - profile
                - email
                - read:records
                - write:records
                response_types_supported:
                - code
                grant_types_supported:
                - authorization_code
                - client_credentials
                - refresh_token
                token_endpoint_auth_methods_supported:
                - client_secret_basic
                - client_secret_post
                code_challenge_methods_supported:
                - S256
    servers:
    - url: '{instance_url}/api/v1'
      description: Base API URL
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL (without /api/v1)
    - url: '{instance_url}'
      description: Root URL (used for MCP endpoints mounted at /mcp)
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL
  /.well-known/oauth-authorization-server:
    get:
      tags:
      - OpenID Connect
      summary: OAuth 2.0 Authorization Server Metadata
      description: 'OAuth 2.0 Authorization Server Metadata Endpoint (RFC 8414).


        Returns the same metadata as the OpenID Connect Discovery endpoint

        but at the RFC 8414 standard path. MCP clients like Claude Code use

        this endpoint for discovery instead of openid-configuration.


        Note: This endpoint does not require authentication.'
      operationId: oauthAuthorizationServerMetadata
      security: []
      servers:
      - url: /
        description: Root URL (not /api/v1)
      responses:
        '200':
          description: Authorization server metadata
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OpenIDConfiguration'
              example:
                issuer: https://api.pipeshub.com
                authorization_endpoint: https://api.pipeshub.com/oauth2/authorize
                token_endpoint: https://api.pipeshub.com/oauth2/token
                userinfo_endpoint: https://api.pipeshub.com/oauth2/userinfo
                revocation_endpoint: https://api.pipeshub.com/oauth2/revoke
                introspection_endpoint: https://api.pipeshub.com/oauth2/introspect
                jwks_uri: https://api.pipeshub.com/.well-known/jwks.json
                scopes_supported:
                - openid
                - profile
                - email
                - read:records
                - write:records
                response_types_supported:
                - code
                grant_types_supported:
                - authorization_code
                - client_credentials
                - refresh_token
                token_endpoint_auth_methods_supported:
                - client_secret_basic
                - client_secret_post
                code_challenge_methods_supported:
                - S256
    servers:
    - url: '{instance_url}/api/v1'
      description: Base API URL
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL (without /api/v1)
    - url: '{instance_url}'
      description: Root URL (used for MCP endpoints mounted at /mcp)
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL
  /.well-known/jwks.json:
    get:
      tags:
      - OpenID Connect
      summary: JSON Web Key Set
      description: 'JSON Web Key Set Endpoint (RFC 7517).


        Returns the public keys used to verify JWT signatures for ID tokens

        and access tokens.


        Use Cases:


        - Verifying ID token signatures


        - Verifying access token signatures (if JWT-based)


        Note:


        - For HS256 (symmetric) signing, this returns empty keys


        - For RS256 (asymmetric) signing, returns public RSA keys


        - Keys should be cached with appropriate TTL'
      operationId: jwks
      security: []
      servers:
      - url: /
        description: Root URL (not /api/v1)
      responses:
        '200':
          description: JSON Web Key Set
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/JWKS'
              example:
                keys:
                - kty: RSA
                  use: sig
                  alg: RS256
                  kid: key-1
                  n: 0vx7agoebG...
                  e: AQAB
    servers:
    - url: '{instance_url}/api/v1'
      description: Base API URL
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL (without /api/v1)
    - url: '{instance_url}'
      description: Root URL (used for MCP endpoints mounted at /mcp)
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL
  /.well-known/oauth-protected-resource/mcp:
    get:
      tags:
      - OpenID Connect
      summary: OAuth Protected Resource Metadata
      description: 'OAuth Protected Resource Metadata Endpoint (RFC 9728).


        Returns metadata about the protected resource including the resource

        identifier, authorization servers, supported scopes, and bearer token methods.


        Use Cases:


        - Discovering which authorization server to use for this resource


        - Determining supported scopes and bearer token methods


        - MCP client auto-configuration


        Note: This endpoint does not require authentication.'
      operationId: oauthProtectedResource
      security: []
      servers:
      - url: /
        description: Root URL (not /api/v1)
      responses:
        '200':
          description: Protected resource metadata
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthProtectedResourceMetadata'
              example:
                resource: https://api.pipeshub.com/mcp
                authorization_servers:
                - https://api.pipeshub.com
                scopes_supported:
                - read:records
                - write:records
                - admin:connectors
                bearer_methods_supported:
                - header
                resource_documentation: https://api.pipeshub.com/api/v1/docs
    servers:
    - url: '{instance_url}/api/v1'
      description: Base API URL
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL (without /api/v1)
    - url: '{instance_url}'
      description: Root URL (used for MCP endpoints mounted at /mcp)
      variables:
        instance_url:
          default: https://app.pipeshub.com
          description: Base server URL
components:
  schemas:
    OpenIDConfiguration:
      type: object
      description: 'OpenID Connect Discovery Response (RFC 8414).

        Contains authorization server metadata.

        '
      properties:
        issuer:
          type: string
          format: uri
          description: Authorization server issuer URL
        authorization_endpoint:
          type: string
          format: uri
          description: OAuth authorization endpoint
        token_endpoint:
          type: string
          format: uri
          description: OAuth token endpoint
        userinfo_endpoint:
          type: string
          format: uri
          description: OpenID Connect UserInfo endpoint
        revocation_endpoint:
          type: string
          format: uri
          description: Token revocation endpoint
        introspection_endpoint:
          type: string
          format: uri
          description: Token introspection endpoint
        jwks_uri:
          type: string
          format: uri
          description: JSON Web Key Set endpoint
        scopes_supported:
          type: array
          items:
            type: string
          description: Supported OAuth scopes
          example:
          - openid
          - profile
          - email
          - read:records
          - write:records
        response_types_supported:
          type: array
          items:
            type: string
          description: Supported OAuth response types
          example:
          - code
        grant_types_supported:
          type: array
          items:
            type: string
          description: Supported grant types
          example:
          - authorization_code
          - client_credentials
          - refresh_token
        token_endpoint_auth_methods_supported:
          type: array
          items:
            type: string
          description: Supported client authentication methods
          example:
          - client_secret_basic
          - client_secret_post
        subject_types_supported:
          type: array
          items:
            type: string
          description: Supported subject identifier types
          example:
          - public
        id_token_signing_alg_values_supported:
          type: array
          items:
            type: string
          description: Supported ID token signing algorithms
          example:
          - HS256
          - RS256
        claims_supported:
          type: array
          items:
            type: string
          description: Supported claims in ID tokens/UserInfo
          example:
          - user_id
          - iss
          - aud
          - exp
          - iat
          - email
          - name
        code_challenge_methods_supported:
          type: array
          items:
            type: string
          description: Supported PKCE code challenge methods (only `S256`)
          example:
          - S256
    OAuthProtectedResourceMetadata:
      type: object
      description: 'OAuth Protected Resource Metadata (RFC 9728).

        Describes the protected resource, its authorization servers, supported scopes, and bearer token methods.

        '
      required:
      - resource
      - authorization_servers
      properties:
        resource:
          type: string
          format: uri
          description: Protected resource identifier
        authorization_servers:
          type: array
          items:
            type: string
            format: uri
          description: Authorization servers that can issue tokens for this resource
        scopes_supported:
          type: array
          items:
            type: string
          description: OAuth scopes supported by this resource
          example:
          - read:records
          - write:records
          - admin:connectors
        bearer_methods_supported:
          type: array
          items:
            type: string
          description: Methods supported for sending bearer tokens
          example:
          - header
        resource_documentation:
          type: string
          format: uri
          description: URL to human-readable documentation for the resource
    JWKS:
      type: object
      description: 'JSON Web Key Set (RFC 7517).

        Contains public keys for verifying token signatures.

        '
      properties:
        keys:
          type: array
          items:
            $ref: '#/components/schemas/JWK'
          description: Array of JSON Web Keys
    JWK:
      type: object
      description: 'JSON Web Key (RFC 7517).

        Public key for verifying JWT signatures.

        '
      properties:
        kty:
          type: string
          description: Key type
          example: RSA
        use:
          type: string
          description: Key use (sig = signature)
          example: sig
        alg:
          type: string
          description: Algorithm
          example: RS256
        kid:
          type: string
          description: Key ID
        n:
          type: string
          description: RSA modulus (base64url encoded)
        e:
          type: string
          description: RSA exponent (base64url encoded)
          example: AQAB
    OAuthUserInfoResponse:
      type: object
      description: 'OpenID Connect UserInfo Response.

        Contains claims about the authenticated user.

        '
      properties:
        user_id:
          type: string
          description: User ID
        name:
          type: string
          description: Full name
        given_name:
          type: string
          description: First name
        family_name:
          type: string
          description: Last name
        email:
          type: string
          format: email
          description: Email address
        email_verified:
          type: boolean
          description: Whether email has been verified
        picture:
          type: string
          format: uri
          description: Profile picture URL
        updated_at:
          type: integer
          description: Last profile update timestamp (Unix epoch)
      required:
      - user_id
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'JWT Bearer token for authenticated requests.


        A personal access token (see the **Personal Access Tokens** tag) is a

        `phpat_`-prefixed variant of this same JWT — e.g. `phpat_eyJhbGci...`.

        The prefix is display-only, added for secret-scanner detectability; the

        gateway strips it before verifying the token, so send it exactly as

        issued, prefix included.

        '
    scopedToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Scoped JWT token for service-to-service authentication.

        Format: "Bearer {scoped_token}"

        Required scopes vary by endpoint.

        '
    oauth2:
      type: oauth2
      description: 'OAuth 2.0 authentication with fine-grained scopes.

        Supports authorization_code (with PKCE) and client_credentials flows.

        OAuth tokens are Bearer JWTs — use the same Authorization header as regular tokens.

        For **client_credentials**, machine JWTs may use `userId === client_id`; the Node gateway resolves the OAuth app creator — see **OAuth Provider** tag.

        '
      flows:
        authorizationCode:
          authorizationUrl: /api/v1/oauth2/authorize
          tokenUrl: /api/v1/oauth2/token
          refreshUrl: /api/v1/oauth2/token
          scopes:
            openid: OpenID Connect authentication
            profile: User profile information
            email: User email address
            offline_access: Offline access (refresh tokens)
            org:read: Read organization information
            org:write: Update organization settings
            org:admin: Full organization administration
            user:read: Read user profiles
            user:write: Update user profiles
            user:invite: Invite new users
            user:delete: Delete users
            usergroup:read: Read user groups
            usergroup:write: Create and manage user groups
            team:read: Read team information
            team:write: Create and manage teams
            kb:read: Read knowledge bases and records
            kb:write: Create and update knowledge bases
            kb:delete: Delete knowledge bases and records
            kb:upload: Upload files to knowledge bases
            semantic:read: Read semantic search results and history
            semantic:write: Execute semantic search
            semantic:delete: Delete semantic search history
            conversation:read: Read conversations
            conversation:write: Create and manage conversations
            conversation:chat: Send messages in conversations
            project:read: Read projects and their conversations
            project:write: Create and manage projects
            project:delete: Delete projects
            agent:read: Read AI agents
            agent:write: Create and manage AI agents
            agent:execute: Execute AI agents
            connector:read: Read connector configurations
            connector:write: Create and update connectors
            connector:sync: Trigger connector synchronization
            connector:delete: Delete connectors
            config:read: Read system configuration
            config:write: Update system configuration
            crawl:read: Read crawling jobs
            crawl:write: Create and manage crawling jobs
            crawl:delete: Delete crawling jobs
        clientCredentials:
          tokenUrl: /api/v1/oauth2/token
          scopes:
            openid: OpenID Connect authentication
            profile: User profile information
            email: User email address
            offline_access: Offline access (refresh tokens)
            org:read: Read organization information
            org:write: Update organization settings
            org:admin: Full organization administration
            user:read: Read user profiles
            user:write: Update user profiles
            user:invite: Invite new users
            user:delete: Delete users
            usergroup:read: Read user groups
            usergroup:write: Create and manage user groups
            team:read: Read team information
            team:write: Create and manage teams
            kb:read: Read knowledge bases and records
            kb:write: Create and update knowledge bases
            kb:delete: Delete knowledge bases and records
            kb:upload: Upload files to knowledge bases
            semantic:write: Execute semantic search
            semantic:read: Read semantic search results and history
            semantic:delete: Delete semantic search history
            conversation:read: Read conversations
            conversation:write: Create and manage conversations
            conversation:chat: Send messages in conversations
            project:read: Read projects and their conversations
            project:write: Create and manage projects
            project:delete: Delete projects
            agent:read: Read AI agents
            agent:write: Create and manage AI agents
            agent:execute: Execute AI agents
            connector:read: Read connector configurations
            connector:write: Create and update connectors
            connector:sync: Trigger connector synchronization
            connector:delete: Delete connectors
            config:read: Read system configuration
            config:write: Update system configuration
            crawl:read: Read crawling jobs
            crawl:write: Create and manage crawling jobs
x-refined-from:
- pipeshub-openapi.yaml
- pipeshub-openapi.yml