True Fit Auth API
Endpoints to allow saving and logging in to a True Fit account.
Endpoints to allow saving and logging in to a True Fit account.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/true-fit-auth-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: True Fit - Consumer Auth API
description: These APIs can be used to create a custom True Fit integration.
version: '3.0'
servers:
- url: /profile/public/v3/{tla}
tags:
- name: Auth
description: Endpoints to allow saving and logging in to a True Fit account.
paths:
/auth:
get:
tags:
- Auth
summary: Get the current authentication state
parameters:
- name: X-TF-UserToken
in: header
description: The session token for the current user.
required: true
style: simple
explode: false
schema:
type: string
responses:
'200':
description: The authentication state was successfully retrieved.
headers:
X-TF-UserToken:
description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
style: simple
explode: false
schema:
type: string
X-TF-UserTokenMaxAge:
description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
style: simple
explode: false
schema:
type: integer
content:
application/json:
schema:
$ref: '#/components/schemas/AuthenticationState'
operationId: getAuth
x-operation-id-source: derived
/auth/save:
post:
tags:
- Auth
summary: Save a True Fit account using an email address and password
parameters:
- name: X-TF-UserToken
in: header
description: The session token for the current user.
required: true
style: simple
explode: false
schema:
type: string
- name: locale
in: query
description: Identifier specifying the locale of the user (if available; falls back to en_US). Use an ISO 639 language code followed by an ISO 3166 country code, e.g. en_US.
required: false
style: form
explode: true
schema:
type: string
requestBody:
$ref: '#/components/requestBodies/EmailCredentials'
responses:
'200':
description: The account was successfully saved.
headers:
X-TF-UserToken:
description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
style: simple
explode: false
schema:
type: string
X-TF-UserTokenMaxAge:
description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
style: simple
explode: false
schema:
type: integer
'400':
description: The save attempt failed.
content:
EmailNotUnique:
examples:
response:
value:
reason: EmailNotUnique
EmailNotValid:
examples:
response:
value:
reason: EmailNotValid
PasswordNotSecure:
examples:
response:
value:
reason: PasswordNotSecure
AuthDisabledForLocale:
examples:
response:
value:
reason: AuthDisabledForLocale
UnexpectedError:
examples:
response:
value:
reason: UnexpectedError
operationId: postAuthSave
x-operation-id-source: derived
/auth/login:
post:
tags:
- Auth
summary: Log in to a True Fit account using an email address and password
parameters:
- name: X-TF-UserToken
in: header
description: The session token for the current user.
required: true
style: simple
explode: false
schema:
type: string
- name: locale
in: query
description: Identifier specifying the language that the forgot password email uses (if available; falls back to en_US). Use an ISO 639 language code followed by an ISO 3166 country code, e.g. en_US.
required: false
style: form
explode: true
schema:
type: string
requestBody:
$ref: '#/components/requestBodies/LoginEmailCredentials'
responses:
'200':
description: The login was successful.
headers:
X-TF-UserToken:
description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
style: simple
explode: false
schema:
type: string
X-TF-UserTokenMaxAge:
description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
style: simple
explode: false
schema:
type: integer
'401':
description: The login was not successful. If the reason is "MustChangePassword", the client should present the user with an interface to change their password. See /auth/update
content:
MustChangePassword:
examples:
response:
value:
reason: MustChangePassword
AuthDisabledForLocale:
examples:
response:
value:
reason: AuthDisabledForLocale
LoginFailed:
examples:
response:
value:
reason: InvalidCredentials
operationId: postAuthLogin
x-operation-id-source: derived
/auth/logout:
post:
tags:
- Auth
summary: Logs the current user out of their True Fit account
parameters:
- name: X-TF-UserToken
in: header
description: The session token for the current user.
required: true
style: simple
explode: false
schema:
type: string
responses:
'200':
description: The logout was successful.
headers:
X-TF-UserToken:
description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
style: simple
explode: false
schema:
type: string
X-TF-UserTokenMaxAge:
description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
style: simple
explode: false
schema:
type: integer
operationId: postAuthLogout
x-operation-id-source: derived
/auth/update:
post:
tags:
- Auth
summary: Update an email address and/or password for a saved True Fit account
parameters:
- name: X-TF-UserToken
in: header
description: The session token for the current user.
required: true
style: simple
explode: false
schema:
type: string
requestBody:
$ref: '#/components/requestBodies/UpdateEmailCredentials'
responses:
'200':
description: The update was successful.
headers:
X-TF-UserToken:
description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
style: simple
explode: false
schema:
type: string
X-TF-UserTokenMaxAge:
description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
style: simple
explode: false
schema:
type: integer
'400':
description: The update was unsuccessful due to an issue with the new email or password.
content:
EmailNotUnique:
examples:
response:
value:
reason: EmailNotUnique
EmailNotValid:
examples:
response:
value:
reason: EmailNotValid
PasswordNotSecure:
examples:
response:
value:
reason: PasswordNotSecure
UnexpectedError:
examples:
response:
value:
reason: UnexpectedError
'401':
description: The update was unsuccessful due to the current email or password not being valid.
content:
InvalidCredentials:
examples:
response:
value:
reason: InvalidCredentials
operationId: postAuthUpdate
x-operation-id-source: derived
/auth/forgot:
post:
tags:
- Auth
summary: Request a password reset e-mail for a forgotten password
parameters:
- name: X-TF-UserToken
in: header
description: The session token for the current user.
required: true
style: simple
explode: false
schema:
type: string
- name: locale
in: query
description: Identifier specifying the language that the forgot password email uses (if available; falls back to en_US). Use an ISO 639 language code followed by an ISO 3166 country code, e.g. en_US.
required: false
style: form
explode: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/body_1'
required: true
responses:
'200':
description: A reset password e-mail was sent if True Fit found an account with the requested e-mail address.
headers:
X-TF-UserToken:
description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
style: simple
explode: false
schema:
type: string
X-TF-UserTokenMaxAge:
description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
style: simple
explode: false
schema:
type: integer
operationId: postAuthForgot
x-operation-id-source: derived
/auth/recover:
post:
tags:
- Auth
summary: Recover a forgotten password via a password reset token sent to the user after…
parameters:
- name: X-TF-UserToken
in: header
description: The session token for the current user.
required: true
style: simple
explode: false
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/body_2'
required: true
responses:
'200':
description: The recover operation was successful and the user has been authenticated with the newPassword.
headers:
X-TF-UserToken:
description: The updated token for the user. This updated token should be used on all following requests. This header is only present when the token has cycled.
style: simple
explode: false
schema:
type: string
X-TF-UserTokenMaxAge:
description: This will be most useful when storing the token as a cookie. The value is the suggested max age of the token (in seconds).
style: simple
explode: false
schema:
type: integer
'400':
description: Either the emailAddress or passwordToken was invalid, or the newPassword was not secure.
operationId: postAuthRecover
x-operation-id-source: derived
components:
schemas:
body_1:
required:
- emailAddress
type: object
properties:
emailAddress:
type: string
LoginEmailCredentials:
allOf:
- $ref: '#/components/schemas/EmailCredentials'
- type: object
properties:
keepSignedIn:
type: boolean
description: If set to `false` the session will be automatically logged out after a period of time. Defaults to `true`.
UpdateEmailCredentials:
allOf:
- $ref: '#/components/schemas/EmailCredentials'
- type: object
properties:
newEmailAddress:
type: string
description: The email address to update to.
newPassword:
type: string
description: The password to update to.
EmailCredentials:
required:
- emailAddress
- password
type: object
properties:
emailAddress:
type: string
password:
type: string
AuthenticationState_emailCredential:
type: object
properties:
maskedEmail:
type: string
example: j***s@t***m
AuthenticationState:
required:
- isAccountSaved
type: object
properties:
isCredentialSaved:
type: boolean
emailCredential:
$ref: '#/components/schemas/AuthenticationState_emailCredential'
body_2:
required:
- emailAddress
- newPassword
- passwordToken
type: object
properties:
emailAddress:
type: string
passwordToken:
type: string
newPassword:
type: string
requestBodies:
UpdateEmailCredentials:
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateEmailCredentials'
required: true
EmailCredentials:
content:
application/json:
schema:
$ref: '#/components/schemas/EmailCredentials'
required: true
LoginEmailCredentials:
content:
application/json:
schema:
$ref: '#/components/schemas/LoginEmailCredentials'
required: true
x-explorer-enabled: false