SparkyFitness Authentication API

The Authentication API from SparkyFitness — 4 operation(s) for authentication.

Operations 4

GET /auth/settings Get public authentication settings and available OIDC providers #
GET /auth/mfa-factors Get enabled MFA factors for a user by email #
POST /auth/web-login/register-ticket Mint a single-use, short-lived passkey registration ticket #
POST /auth/web-login/redeem-ticket Redeem a single-use passkey registration ticket #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sparkyfitness-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sparkyfitness-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: SparkyFitness Authentication API
  version: 1.0.0
  description: API documentation for the SparkyFitness application, providing a comprehensive guide to all available endpoints.
  contact:
    name: SparkyFitness Support
servers:
- url: https://{host}/api
  description: Self-hosted SparkyFitness instance (the operator supplies the host). The upstream spec declares the relative base "/api".
  variables:
    host:
      default: sparkyfitness.example.com
      description: Hostname of your own SparkyFitness deployment. SparkyFitness is self-hosted; there is no vendor-operated API host.
security:
- apiKeyAuth: []
tags:
- name: Authentication
paths:
  /auth/settings:
    get:
      summary: Get public authentication settings and available OIDC providers
      tags:
      - Authentication
      responses:
        '200':
          description: Login settings and OIDC providers
      operationId: getAuthSettings
      x-operation-id-source: derived
  /auth/mfa-factors:
    get:
      summary: Get enabled MFA factors for a user by email
      tags:
      - Authentication
      parameters:
      - in: query
        name: email
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Enabled MFA factors
        '400':
          description: Email is required
      operationId: getAuthMfaFactors
      x-operation-id-source: derived
  /auth/web-login/register-ticket:
    post:
      summary: Mint a single-use, short-lived passkey registration ticket
      description: Authenticated with the caller's Bearer session token. Requires a fresh session (recent login); returns 403 SESSION_NOT_FRESH otherwise so the client can re-authenticate. The returned ticket is handed to the browser registration page so the raw session token never appears in a URL.
      tags:
      - Authentication
      responses:
        '200':
          description: Ticket minted
        '401':
          description: Missing or invalid session
        '403':
          description: Session not fresh; re-authentication required
      operationId: postAuthWebLoginRegisterTicket
      x-operation-id-source: derived
  /auth/web-login/redeem-ticket:
    post:
      summary: Redeem a single-use passkey registration ticket
      description: Public (the ticket is the credential) and rate-limited. Returns the session token in the JSON body exactly once; the ticket is then consumed.
      tags:
      - Authentication
      responses:
        '200':
          description: Session token returned
        '400':
          description: Invalid, used, or expired ticket
      operationId: postAuthWebLoginRedeemTicket
      x-operation-id-source: derived
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: API key authentication via x-api-key header.
x-provenance:
  generated: '2026-08-27'
  method: derived
  source: https://github.com/CodeWithCJ/SparkyFitness — assembled from the project's own swagger-jsdoc configuration (SparkyFitnessServer/config/swagger.ts) and the 419 @swagger JSDoc blocks in SparkyFitnessServer/routes/**, using the same scan paths and the same cookieAuth->apiKeyAuth post-processing the server applies. This is the identical document a running instance serves at GET /api/api-docs/json (Swagger UI at /api/api-docs/swagger, ReDoc at /api/api-docs/redoc).
  note: 'Not fetched from a live host: SparkyFitness is self-hosted and the project operates no public instance, so the contract can only be read from the source that generates it. Upstream sets no operationIds; paths+methods are the stable identifiers.'
  upstream_version: server package.json 1.6.4 (release v1.6.4, 2026-08-27)