True Fit Auth API

Endpoints to allow saving and logging in to a True Fit account.

Operations 7

GET /auth Get the current authentication state #
POST /auth/save Save a True Fit account using an email address and password #
POST /auth/login Log in to a True Fit account using an email address and password #
POST /auth/logout Logs the current user out of their True Fit account #
POST /auth/update Update an email address and/or password for a saved True Fit account #
POST /auth/forgot Request a password reset e-mail for a forgotten password #
POST /auth/recover Recover a forgotten password via a password reset token sent to the user after… #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/true-fit-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

true-fit-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: True Fit - Consumer Auth API
  description: These APIs can be used to create a custom True Fit integration.
  version: '3.0'
servers:
- url: /profile/public/v3/{tla}
tags:
- name: Auth
  description: Endpoints to allow saving and logging in to a True Fit account.
paths:
  /auth:
    get:
      tags:
      - Auth
      summary: Get the current authentication state
      parameters:
      - name: X-TF-UserToken
        in: header
        description: The session token for the current user.
        required: true
        style: simple
        explode: false
        schema:
          type: string
      responses:
        '200':
          description: The authentication state was successfully retrieved.
          headers:
            X-TF-UserToken:
              description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
              style: simple
              explode: false
              schema:
                type: string
            X-TF-UserTokenMaxAge:
              description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
              style: simple
              explode: false
              schema:
                type: integer
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthenticationState'
      operationId: getAuth
      x-operation-id-source: derived
  /auth/save:
    post:
      tags:
      - Auth
      summary: Save a True Fit account using an email address and password
      parameters:
      - name: X-TF-UserToken
        in: header
        description: The session token for the current user.
        required: true
        style: simple
        explode: false
        schema:
          type: string
      - name: locale
        in: query
        description: Identifier specifying the locale of the user (if available; falls back to en_US). Use an ISO 639 language code followed by an ISO 3166 country code, e.g. en_US.
        required: false
        style: form
        explode: true
        schema:
          type: string
      requestBody:
        $ref: '#/components/requestBodies/EmailCredentials'
      responses:
        '200':
          description: The account was successfully saved.
          headers:
            X-TF-UserToken:
              description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
              style: simple
              explode: false
              schema:
                type: string
            X-TF-UserTokenMaxAge:
              description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
              style: simple
              explode: false
              schema:
                type: integer
        '400':
          description: The save attempt failed.
          content:
            EmailNotUnique:
              examples:
                response:
                  value:
                    reason: EmailNotUnique
            EmailNotValid:
              examples:
                response:
                  value:
                    reason: EmailNotValid
            PasswordNotSecure:
              examples:
                response:
                  value:
                    reason: PasswordNotSecure
            AuthDisabledForLocale:
              examples:
                response:
                  value:
                    reason: AuthDisabledForLocale
            UnexpectedError:
              examples:
                response:
                  value:
                    reason: UnexpectedError
      operationId: postAuthSave
      x-operation-id-source: derived
  /auth/login:
    post:
      tags:
      - Auth
      summary: Log in to a True Fit account using an email address and password
      parameters:
      - name: X-TF-UserToken
        in: header
        description: The session token for the current user.
        required: true
        style: simple
        explode: false
        schema:
          type: string
      - name: locale
        in: query
        description: Identifier specifying the language that the forgot password email uses (if available; falls back to en_US). Use an ISO 639 language code followed by an ISO 3166 country code, e.g. en_US.
        required: false
        style: form
        explode: true
        schema:
          type: string
      requestBody:
        $ref: '#/components/requestBodies/LoginEmailCredentials'
      responses:
        '200':
          description: The login was successful.
          headers:
            X-TF-UserToken:
              description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
              style: simple
              explode: false
              schema:
                type: string
            X-TF-UserTokenMaxAge:
              description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
              style: simple
              explode: false
              schema:
                type: integer
        '401':
          description: The login was not successful. If the reason is "MustChangePassword", the client should present the user with an interface to change their password. See /auth/update
          content:
            MustChangePassword:
              examples:
                response:
                  value:
                    reason: MustChangePassword
            AuthDisabledForLocale:
              examples:
                response:
                  value:
                    reason: AuthDisabledForLocale
            LoginFailed:
              examples:
                response:
                  value:
                    reason: InvalidCredentials
      operationId: postAuthLogin
      x-operation-id-source: derived
  /auth/logout:
    post:
      tags:
      - Auth
      summary: Logs the current user out of their True Fit account
      parameters:
      - name: X-TF-UserToken
        in: header
        description: The session token for the current user.
        required: true
        style: simple
        explode: false
        schema:
          type: string
      responses:
        '200':
          description: The logout was successful.
          headers:
            X-TF-UserToken:
              description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
              style: simple
              explode: false
              schema:
                type: string
            X-TF-UserTokenMaxAge:
              description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
              style: simple
              explode: false
              schema:
                type: integer
      operationId: postAuthLogout
      x-operation-id-source: derived
  /auth/update:
    post:
      tags:
      - Auth
      summary: Update an email address and/or password for a saved True Fit account
      parameters:
      - name: X-TF-UserToken
        in: header
        description: The session token for the current user.
        required: true
        style: simple
        explode: false
        schema:
          type: string
      requestBody:
        $ref: '#/components/requestBodies/UpdateEmailCredentials'
      responses:
        '200':
          description: The update was successful.
          headers:
            X-TF-UserToken:
              description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
              style: simple
              explode: false
              schema:
                type: string
            X-TF-UserTokenMaxAge:
              description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
              style: simple
              explode: false
              schema:
                type: integer
        '400':
          description: The update was unsuccessful due to an issue with the new email or password.
          content:
            EmailNotUnique:
              examples:
                response:
                  value:
                    reason: EmailNotUnique
            EmailNotValid:
              examples:
                response:
                  value:
                    reason: EmailNotValid
            PasswordNotSecure:
              examples:
                response:
                  value:
                    reason: PasswordNotSecure
            UnexpectedError:
              examples:
                response:
                  value:
                    reason: UnexpectedError
        '401':
          description: The update was unsuccessful due to the current email or password not being valid.
          content:
            InvalidCredentials:
              examples:
                response:
                  value:
                    reason: InvalidCredentials
      operationId: postAuthUpdate
      x-operation-id-source: derived
  /auth/forgot:
    post:
      tags:
      - Auth
      summary: Request a password reset e-mail for a forgotten password
      parameters:
      - name: X-TF-UserToken
        in: header
        description: The session token for the current user.
        required: true
        style: simple
        explode: false
        schema:
          type: string
      - name: locale
        in: query
        description: Identifier specifying the language that the forgot password email uses (if available; falls back to en_US). Use an ISO 639 language code followed by an ISO 3166 country code, e.g. en_US.
        required: false
        style: form
        explode: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/body_1'
        required: true
      responses:
        '200':
          description: A reset password e-mail was sent if True Fit found an account with the requested e-mail address.
          headers:
            X-TF-UserToken:
              description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
              style: simple
              explode: false
              schema:
                type: string
            X-TF-UserTokenMaxAge:
              description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
              style: simple
              explode: false
              schema:
                type: integer
      operationId: postAuthForgot
      x-operation-id-source: derived
  /auth/recover:
    post:
      tags:
      - Auth
      summary: Recover a forgotten password via a password reset token sent to the user after…
      parameters:
      - name: X-TF-UserToken
        in: header
        description: The session token for the current user.
        required: true
        style: simple
        explode: false
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/body_2'
        required: true
      responses:
        '200':
          description: The recover operation was successful and the user has been authenticated with the newPassword.
          headers:
            X-TF-UserToken:
              description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
              style: simple
              explode: false
              schema:
                type: string
            X-TF-UserTokenMaxAge:
              description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
              style: simple
              explode: false
              schema:
                type: integer
        '400':
          description: Either the emailAddress or passwordToken was invalid, or the newPassword was not secure.
      operationId: postAuthRecover
      x-operation-id-source: derived
components:
  schemas:
    body_1:
      required:
      - emailAddress
      type: object
      properties:
        emailAddress:
          type: string
    LoginEmailCredentials:
      allOf:
      - $ref: '#/components/schemas/EmailCredentials'
      - type: object
        properties:
          keepSignedIn:
            type: boolean
            description: If set to `false` the session will be automatically logged out after a period of time. Defaults to `true`.
    UpdateEmailCredentials:
      allOf:
      - $ref: '#/components/schemas/EmailCredentials'
      - type: object
        properties:
          newEmailAddress:
            type: string
            description: The email address to update to.
          newPassword:
            type: string
            description: The password to update to.
    EmailCredentials:
      required:
      - emailAddress
      - password
      type: object
      properties:
        emailAddress:
          type: string
        password:
          type: string
    AuthenticationState_emailCredential:
      type: object
      properties:
        maskedEmail:
          type: string
          example: j***s@t***m
    AuthenticationState:
      required:
      - isAccountSaved
      type: object
      properties:
        isCredentialSaved:
          type: boolean
        emailCredential:
          $ref: '#/components/schemas/AuthenticationState_emailCredential'
    body_2:
      required:
      - emailAddress
      - newPassword
      - passwordToken
      type: object
      properties:
        emailAddress:
          type: string
        passwordToken:
          type: string
        newPassword:
          type: string
  requestBodies:
    UpdateEmailCredentials:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/UpdateEmailCredentials'
      required: true
    EmailCredentials:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/EmailCredentials'
      required: true
    LoginEmailCredentials:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LoginEmailCredentials'
      required: true
x-explorer-enabled: false