Ritten OAUTH API

OAuth 2.0 token endpoint for obtaining access tokens. This is the recommended way to authenticate with the Ritten External API.

Operations 1

POST /oauth/token Obtain an access token (OAuth 2.0 client_credentials) #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/ritten-oauth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

ritten-oauth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: External OAUTH API
  x-logo:
    url: https://storage.googleapis.com/ritten-ops-public-logos/rittenBanner
    backgroundColor: '#FFFFFF'
    altText: Ritten Logo
  description: 'For Ritten Integrating Partners


    ## Authentication


    - Request an access token with your provided integration credentials (`client_id` and `client_secret`) by calling our token endpoint:

    ```bash

    curl https://api.ritten.io/v1/oauth/token \

    -X POST \

    -H ''content-type: application/json'' \

    -d ''{"client_id":"${client_id}","client_secret":"${client_secret}","audience":"https://external-api.ritten.io","grant_type":"client_credentials"}''

    ```

    - Take the `access_token` from the response and use that as…'
  version: 1.0.0
servers:
- url: https://api.ritten.io/v1
tags:
- name: OAuth
  description: 'OAuth 2.0 token endpoint for obtaining access tokens. This is the

    recommended way to authenticate with the Ritten External API.'
paths:
  /oauth/token:
    post:
      tags:
      - OAuth
      summary: Obtain an access token (OAuth 2.0 client_credentials)
      description: 'Exchanges integrator credentials for a 24-hour access token to use as a `Bearer`

        token on subsequent API calls. This endpoint is **unauthenticated** at the gateway

        layer — your `client_secret` in the request body is the authentication. Ritten

        forwards the credentials to Auth0, validates the response, and caches the resulting

        token server-side so repeated calls do not consume your Auth0 mint quota.


        The response shape mirrors the OAuth 2.0 / Auth0 `/oauth/token` response so existing

        OAuth2 client libraries work without modification.


        **Mint quota interaction:** the per-app token mint quota (2/hour, 3/day) counts

        mints actually performed against Auth0. Because this endpoint caches server-side,

        repeated calls within a 24-hour window typically result in zero additional Auth0

        mints — so calling here is far cheaper against your quota than calling Auth0

        directly. See the Authentication and Rate Limiting sections above.'
      operationId: postOAuthToken
      security: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OAuthTokenRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/OAuthTokenRequest'
      responses:
        200:
          description: Access token issued.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthTokenResponse'
        400:
          description: 'Malformed request. The `error` field will be one of `invalid_request`,

            `unsupported_grant_type`, or `invalid_audience`.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
        401:
          description: 'Auth0 rejected the supplied credentials (`error: invalid_client` or similar).

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
        429:
          description: 'Rate limit exceeded. Either the per-IP request rate limit on this endpoint,

            or the per-app Auth0 mint quota (2/hour, 3/day) has been reached. Retry

            after a short delay. If 429s persist, inspect whether you are hitting

            per-IP request limits vs. triggering fresh Auth0 mints, then reach out

            to Ritten for support.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
        502:
          description: 'Auth0 was unreachable or returned a 5xx error. Retry — Ritten does not

            cache failed responses.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
components:
  schemas:
    OAuthTokenResponse:
      type: object
      required:
      - access_token
      - token_type
      - expires_in
      properties:
        access_token:
          type: string
          description: The access token to use as a `Bearer` token on subsequent API calls.
        token_type:
          type: string
          example: Bearer
        expires_in:
          type: integer
          format: int64
          description: Token lifetime in seconds (currently 86400 / 24h).
          example: 86400
        scope:
          type: string
          description: Space-separated list of granted scopes (may be empty).
    OAuthTokenRequest:
      type: object
      required:
      - grant_type
      - client_id
      - client_secret
      - audience
      properties:
        grant_type:
          type: string
          enum:
          - client_credentials
          description: OAuth 2.0 grant type. Must be `client_credentials`.
          example: client_credentials
        client_id:
          type: string
          description: Your Auth0 M2M client ID.
        client_secret:
          type: string
          format: password
          writeOnly: true
          description: Your Auth0 M2M client secret.
        audience:
          type: string
          description: 'The audience for the requested token. Must equal the env-specific

            external-api audience (e.g. `https://external-api.ritten.io` in

            production, `https://external-api.beta.ritten.io` in beta).

            '
          example: https://external-api.ritten.io
    OAuthErrorResponse:
      type: object
      required:
      - error
      properties:
        error:
          type: string
          description: 'OAuth 2.0 error code. Common values: `invalid_request`,

            `unsupported_grant_type`, `invalid_audience`, `invalid_client`,

            `bad_gateway`, `rate_limit_exceeded`.

            '
        error_description:
          type: string
          description: Human-readable explanation of the error.