SuperTokens Passwordless API

Passwordless OTP and magic link authentication

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/supertokens-passwordless-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

supertokens-passwordless-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: SuperTokens Core Driver Interface Email Password Passwordless API
  description: The Core Driver Interface (CDI) is the REST API exposed by the supertokens-core HTTP service. Backend SDKs (Node.js, Python, Go) use this API to communicate with the core service for authentication operations including session management, user sign-up/sign-in, email verification, password reset, social login, passwordless authentication, multi-tenancy, and user metadata management.
  version: '5.1'
  contact:
    name: SuperTokens
    url: https://supertokens.com
    email: team@supertokens.com
  license:
    name: Apache-2.0
    url: https://github.com/supertokens/supertokens-core/blob/master/LICENSE.md
servers:
- url: http://{host}:{port}
  description: SuperTokens Core service
  variables:
    host:
      default: localhost
      description: Hostname of the SuperTokens Core instance
    port:
      default: '3567'
      description: Port number of the SuperTokens Core instance
security:
- ApiKeyAuth: []
tags:
- name: Passwordless
  description: Passwordless OTP and magic link authentication
paths:
  /recipe/signinup/code:
    post:
      operationId: createPasswordlessCode
      summary: Create Passwordless Code
      description: Creates a one-time code (OTP) or magic link for passwordless authentication via email or phone.
      tags:
      - Passwordless
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreatePasswordlessCodeRequest'
      responses:
        '200':
          description: Code created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreatePasswordlessCodeResponse'
  /recipe/signinup/code/consume:
    post:
      operationId: consumePasswordlessCode
      summary: Consume Passwordless Code
      description: Validates and consumes a passwordless OTP or magic link code to authenticate the user.
      tags:
      - Passwordless
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConsumePasswordlessCodeRequest'
      responses:
        '200':
          description: Code consumed and user authenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConsumePasswordlessCodeResponse'
components:
  schemas:
    ConsumePasswordlessCodeResponse:
      type: object
      properties:
        status:
          type: string
          enum:
          - OK
          - INCORRECT_USER_INPUT_CODE_ERROR
          - EXPIRED_USER_INPUT_CODE_ERROR
          - RESTART_FLOW_ERROR
        createdNewUser:
          type: boolean
        user:
          $ref: '#/components/schemas/User'
    User:
      type: object
      description: A SuperTokens user object
      properties:
        id:
          type: string
          description: Unique user ID
        emails:
          type: array
          items:
            type: string
        phoneNumbers:
          type: array
          items:
            type: string
        thirdParty:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
              userId:
                type: string
        timeJoined:
          type: integer
          description: Unix timestamp when user joined
        tenantIds:
          type: array
          items:
            type: string
        loginMethods:
          type: array
          items:
            type: object
    CreatePasswordlessCodeRequest:
      type: object
      properties:
        email:
          type: string
          format: email
          description: User email for email-based passwordless
        phoneNumber:
          type: string
          description: Phone number for SMS-based passwordless
        tenantId:
          type: string
    CreatePasswordlessCodeResponse:
      type: object
      properties:
        status:
          type: string
        preAuthSessionId:
          type: string
        codeId:
          type: string
        deviceId:
          type: string
        userInputCode:
          type: string
          description: The OTP code to send to the user
        linkCode:
          type: string
          description: The magic link code
        timeCreated:
          type: integer
        codeLifetime:
          type: integer
    ConsumePasswordlessCodeRequest:
      type: object
      required:
      - preAuthSessionId
      properties:
        preAuthSessionId:
          type: string
        userInputCode:
          type: string
          description: OTP entered by user
        deviceId:
          type: string
        tenantId:
          type: string
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: api-key
      description: SuperTokens Core API key (configured in config.yaml or via environment variable)