Turnkey Users & Policies API

Users, authenticators, API keys, and the policy engine.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/turnkey-users-policies-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

turnkey-users-policies-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Turnkey Organizations Users & Policies API
  description: 'Turnkey is secure wallet infrastructure: an API-first key-management and signing platform that generates private keys and signs payloads inside verifiable secure enclaves (TEEs). The public API is an RPC-style REST API under https://api.turnkey.com/public/v1 split into two families - read-only `query` endpoints and state-changing `submit` activity endpoints. Every request is an HTTP POST carrying an `X-Stamp` (or `X-Stamp-Webauthn`) header containing a digital signature over the exact JSON POST body. The stamp is verified by Turnkey''s secure enclaves before the request is processed and checked against the organization''s policy engine.'
  termsOfService: https://www.turnkey.com/legal/terms
  contact:
    name: Turnkey Support
    url: https://docs.turnkey.com
  version: '1.0'
servers:
- url: https://api.turnkey.com
security:
- apiStamp: []
tags:
- name: Users & Policies
  description: Users, authenticators, API keys, and the policy engine.
paths:
  /public/v1/submit/create_policies:
    post:
      operationId: createPolicies
      tags:
      - Users & Policies
      summary: Create policies
      description: Adds one or more policies to the policy engine that authorizes activities. Activity type ACTIVITY_TYPE_CREATE_POLICIES.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SubmitActivityEnvelope'
      responses:
        '200':
          description: Activity accepted/completed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ActivityResponse'
  /public/v1/submit/create_users:
    post:
      operationId: createUsers
      tags:
      - Users & Policies
      summary: Create users
      description: Adds users to an organization with associated API keys and authenticators. Activity type ACTIVITY_TYPE_CREATE_USERS_V3.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SubmitActivityEnvelope'
      responses:
        '200':
          description: Activity accepted/completed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ActivityResponse'
  /public/v1/submit/create_authenticators:
    post:
      operationId: createAuthenticators
      tags:
      - Users & Policies
      summary: Create authenticators
      description: Registers WebAuthn/passkey authenticators for a user. Activity type ACTIVITY_TYPE_CREATE_AUTHENTICATORS_V2.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SubmitActivityEnvelope'
      responses:
        '200':
          description: Activity accepted/completed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ActivityResponse'
  /public/v1/query/list_users:
    post:
      operationId: listUsers
      tags:
      - Users & Policies
      summary: List users
      description: Lists users in an organization.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OrganizationScopedQuery'
      responses:
        '200':
          description: List of users.
          content:
            application/json:
              schema:
                type: object
  /public/v1/query/list_policies:
    post:
      operationId: listPolicies
      tags:
      - Users & Policies
      summary: List policies
      description: Lists policies in an organization.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OrganizationScopedQuery'
      responses:
        '200':
          description: List of policies.
          content:
            application/json:
              schema:
                type: object
  /public/v1/query/whoami:
    post:
      operationId: whoami
      tags:
      - Users & Policies
      summary: Who am I
      description: Returns the organization and user associated with the stamping credential of the request.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WhoamiRequest'
      responses:
        '200':
          description: Caller identity.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WhoamiResponse'
components:
  schemas:
    WhoamiResponse:
      type: object
      properties:
        organizationId:
          type: string
        organizationName:
          type: string
        userId:
          type: string
        username:
          type: string
    ActivityResponse:
      type: object
      description: Standard activity envelope returned by submit and query endpoints.
      properties:
        activity:
          type: object
          properties:
            id:
              type: string
            organizationId:
              type: string
            status:
              type: string
              enum:
              - ACTIVITY_STATUS_CREATED
              - ACTIVITY_STATUS_PENDING
              - ACTIVITY_STATUS_COMPLETED
              - ACTIVITY_STATUS_FAILED
              - ACTIVITY_STATUS_CONSENSUS_NEEDED
              - ACTIVITY_STATUS_REJECTED
            type:
              type: string
            result:
              type: object
              description: Activity-specific result, e.g. createWalletResult {walletId, addresses[]} or signTransactionResult {signedTransaction} or signRawPayloadResult {r, s, v}.
    WhoamiRequest:
      type: object
      required:
      - organizationId
      properties:
        organizationId:
          type: string
    OrganizationScopedQuery:
      type: object
      required:
      - organizationId
      properties:
        organizationId:
          type: string
    SubmitActivityEnvelope:
      type: object
      description: Common envelope for all submit (mutation) activities. The `type` selects the activity and `parameters` carries the activity-specific body.
      required:
      - type
      - timestampMs
      - organizationId
      - parameters
      properties:
        type:
          type: string
          description: The ACTIVITY_TYPE_* discriminator for this activity.
          example: ACTIVITY_TYPE_CREATE_WALLET
        timestampMs:
          type: string
          description: Client timestamp in milliseconds, replay-protected.
          example: '1746736509954'
        organizationId:
          type: string
          description: The organization or sub-organization id the activity targets.
        parameters:
          type: object
          description: Activity-specific parameters.
  securitySchemes:
    apiStamp:
      type: apiKey
      in: header
      name: X-Stamp
      description: Base64URL-encoded JSON stamp `{publicKey, signature, scheme}` where `signature` is a DER-encoded, hex-encoded signature over the exact JSON POST body produced by the registered API key. `scheme` is one of SIGNATURE_SCHEME_TK_API_P256, SIGNATURE_SCHEME_TK_API_SECP256K1, SIGNATURE_SCHEME_TK_API_ED25519, or SIGNATURE_SCHEME_TK_API_SECP256K1_EIP191. Passkey-stamped requests use the alternate `X-Stamp-Webauthn` header carrying a WebAuthn assertion `{credentialId, authenticatorData, clientDataJson, signature}` (plain JSON, not base64URL-encoded) over a SHA256 hash of the POST body.
    webauthnStamp:
      type: apiKey
      in: header
      name: X-Stamp-Webauthn
      description: Plain-JSON WebAuthn assertion stamp for passkey-authenticated requests.