Sana Authentication API

The Authentication API from Sana — 1 operation(s) for authentication.

OpenAPI Specification

sana-labs-authentication-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Sana Assignments Authentication API
  description: Tenant-scoped REST API for the Sana platform (Sana AI / Sana Agents and Sana Learn). All requests are authenticated with a Bearer access token obtained via the OAuth 2.0 client credentials flow and are scoped to a customer's <domain>.sana.ai tenant. The endpoints below are transcribed from Sana's public API reference and cover platform administration (users, groups, programs, courses, paths, assignments, teamspaces), reporting/insights, and standards-based integration surfaces (xAPI). SCIM 2.0 provisioning is offered at /scim/v2 and is not modeled here. AI agent/assistant capabilities are configured primarily in-product and are not exposed as a public chat-completions endpoint in this reference. No endpoints are fabricated; replace <domain> with your tenant domain.
  termsOfService: https://sanalabs.com/legal
  contact:
    name: Sana
    url: https://docs.sana.ai/api-docs/
  version: '0.0'
servers:
- url: https://<domain>.sana.ai
  description: Tenant-scoped base URL; replace <domain> with your Sana tenant.
security:
- bearerAuth: []
tags:
- name: Authentication
paths:
  /api/token:
    post:
      operationId: createToken
      tags:
      - Authentication
      summary: Request an access token (OAuth 2.0 client credentials).
      description: Exchange client_id and client_secret for a Bearer access token using grant_type=client_credentials. The response includes accessToken, tokenType (bearer), and expiresIn (e.g. 3600 seconds).
      security: []
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                grant_type:
                  type: string
                  example: client_credentials
                client_id:
                  type: string
                client_secret:
                  type: string
                scope:
                  type: string
      responses:
        '200':
          description: Access token issued.
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Bearer access token obtained from POST /api/token via the OAuth 2.0 client credentials flow. Sent as: Authorization: Bearer <accessToken>.'