Verifiable Authentication API

These endpoint allow you to create and manage access tokens to be used in API calls. Unlike most other endpoints, when creating an access token, these do not require an access token to be used. Instead you authenticate via another secure mechanism and in exchange you retrieve an access token.

Operations 8

POST /auth/token/password Password Authentication #
POST /auth/password/reset Resets a password #
POST /auth/password/requestreset Requests a password reset #
POST /auth/token/google Google Authentication #
GET /auth/token List active access tokens #
POST /auth/token/{tokenId}/invalidate Invalidate an access token #
POST /auth/token/invalidate Invalidate multiple access tokens #
POST /auth/oauth/token OAuth Authentication #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/verifiable-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

verifiable-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Verifiable API Documentation Authentication API
  description: '# Introduction


    This document contains the official documentation for the latest version of the Verifiable API.'
  version: 26.12.1.962
servers:
- url: https://discovery.verifiable.com/api
  description: Production
- url: https://discovery-staging.verifiable.com/api
  description: Staging
tags:
- name: Authentication
  description: These endpoint allow you to create and manage access tokens to be used in API calls. Unlike most other endpoints, when creating an access token, these do not require an access token to be used. Instead you authenticate via another secure mechanism and in exchange you retrieve an access token.
paths:
  /auth/token/password:
    post:
      tags:
      - Authentication
      summary: Password Authentication
      description: 'Endpoint for authentication using an email and password for a user already registered at Verifiable. In return you will receive an access token that can be used in the following API calls.


        **Note:** The account may require a password change for successful authentication. If password change is required and `newPassword` is not set the server returns `409 Conflict`.

        If `newPassword` is set but the current `password` is not correct the server returns `403 Forbidden`.


        **Note:** If `newPassword` is set it *must* be different than the current password. If the password is the same the server returns `400 Bad Request`.


        **Note:** When `newPassword` is set and the request returns `200 Ok`, all the active access tokens will be invalidated.'
      operationId: PasswordAuth
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PasswordAuthModel'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponseModel'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '409':
          description: Conflict
        '500':
          description: Server Error
  /auth/password/reset:
    post:
      tags:
      - Authentication
      summary: Resets a password
      description: Endpoint for changing a password using a token.
      operationId: PasswordReset
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PasswordResetRequestModel'
      responses:
        '204':
          description: No Content
        '404':
          description: Not Found
        '400':
          description: Bad Request
        '403':
          description: Forbidden
        '500':
          description: Server Error
  /auth/password/requestreset:
    post:
      tags:
      - Authentication
      summary: Requests a password reset
      description: 'Endpoint for requesting a password reset.


        If the e-mail sent in the body of this request has an account associated with it, a message with a link for changing the password will be sent to it.'
      operationId: RequestPasswordReset
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RequestPasswordResetRequestModel'
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '403':
          description: Forbidden
        '500':
          description: Server Error
  /auth/token/google:
    post:
      tags:
      - Authentication
      summary: Google Authentication
      description: It is possible to use Google Sign-In for authentication with the Verifiable API. In order to do so we follow the Google Sign-In for server-side apps flow. In order to use this flow you must use the `client ID` from Verifiable when signing in to Google and send the authorization code as payload to this endpoint. In return you will receive an access token that can be used in the following API calls. The email address of the user must already be registered at Verifiable.
      operationId: GoogleAuth
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GoogleAuthModel'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponseModel'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '500':
          description: Server Error
  /auth/token:
    get:
      tags:
      - Authentication
      summary: List active access tokens
      description: Returns all access tokens for the current user that are neither expired, nor invalidated.
      operationId: ListActiveAccessTokens
      parameters:
      - name: sortedBy
        in: query
        description: The property by which the returned data will be sorted.
        schema:
          enum:
          - Id
          type: string
      - name: sort
        in: query
        description: If set, the properties and directions the returned data will be sorted by.
        schema:
          type: object
          properties:
            Keys:
              enum:
              - Id
              type: string
            Values:
              enum:
              - Asc
              - Desc
              type: string
      - name: offset
        in: query
        description: The offset for the page to start.
        deprecated: true
        schema:
          type: integer
          format: int32
      - name: cursor
        in: query
        description: The cursor to render the page requested. To load the first page send an empty cursor, then the system will generate the cursors to go to the next and/or previous pages automatically.
        schema:
          type: string
      - name: count
        in: query
        description: The number of items to include in a single page.
        schema:
          type: integer
          format: int32
      - name: sortDirection
        in: query
        description: The direction the returned data will be sorted by.
        schema:
          enum:
          - Asc
          - Desc
          type: string
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessTokenPageModel'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '500':
          description: Server Error
      security:
      - Bearer: []
  /auth/token/{tokenId}/invalidate:
    post:
      tags:
      - Authentication
      summary: Invalidate an access token
      description: Invalidates an access token so that it can no longer be used.
      operationId: InvalidateAccessToken
      parameters:
      - name: tokenId
        in: path
        description: The unique identifier of the access token to be invalidated.
        required: true
        schema:
          type: string
          format: uuid
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '404':
          description: Not Found
        '500':
          description: Server Error
      security:
      - Bearer: []
  /auth/token/invalidate:
    post:
      tags:
      - Authentication
      summary: Invalidate multiple access tokens
      description: Invalidates multiple access tokens that belongs to the user making the request so they can no longer be used.
      operationId: InvalidateAccessTokens
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/InvalidateAllAccessTokensRequestModel'
      responses:
        '204':
          description: No Content
        '401':
          description: Unauthorized
        '500':
          description: Server Error
      security:
      - Bearer: []
  /auth/oauth/token:
    post:
      tags:
      - Authentication
      summary: OAuth Authentication
      description: '**🔒 Premium Feature**


        The OAuth 2.0 (machine-to-machine) and SSO authentication flows are premium features that must be enabled by the Verifiable team.

        - **Availability:** These features are available as add-ons to select Verifiable plans.

        - **Provisioning:** These features require organizational-level provisioning through a one-time configuration by the Verifiable team. To ensure maximum security, endpoints are not enabled by default.

        - **Next Steps:** To enable these authentication methods for your organization, please contact your Customer Success Manager or reach out to our Support Team.


        It is possible to use the OAuth Client Credentials flow to authenticate with the Verifiable API. In order to use this flow, you must use the `client ID` and a `client secret` from Verifiable. You must send the client credentials along with the grant type `client_credentials` in a URL-encoded format.'
      operationId: OAuthToken
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                client_id:
                  type: string
                  format: uuid
                client_secret:
                  type: string
                grant_type:
                  type: string
            encoding:
              client_id:
                style: form
              client_secret:
                style: form
              grant_type:
                style: form
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthTokenResponseModel'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '500':
          description: Server Error
components:
  schemas:
    PasswordResetRequestModel:
      required:
      - newPassword
      - token
      type: object
      properties:
        token:
          type: string
          description: The token received via e-mail.
        newPassword:
          type: string
          description: The new password that will be set to the user associated with the token.
      additionalProperties: false
    PasswordAuthModel:
      required:
      - email
      - password
      type: object
      properties:
        email:
          minLength: 1
          type: string
          description: The email address of a previously registered user.
        password:
          type: string
          description: The password associated with the email address.
        newPassword:
          type: string
          description: If set, the password associated with the email address will be changed to this new password.
        timeToLive:
          type: string
          description: If set, the created token will expire after the duration specified by this parameter. Note that the token will still be expired after 4 weeks of no use, regardless of the time to live. Additionally there might be a limit set for your organization. If the requested time-to-live exceeds this limit the token will be capped to that limit.
          format: timespan
      additionalProperties: false
      example:
        email: john.doe@mail.com
        password: secret
        newPassword: even-more-secret
        timeToLive: 00:30:00
    AuthResponseModel:
      type: object
      properties:
        tokenId:
          type: string
          description: Unique identifier for this token. This can be used to invalidate a token.
          format: uuid
        token:
          type: string
          description: The access token to be used in following API calls.
        email:
          type: string
          description: The e-mail address of the user. It will either be the same e-mail address used on the password authentication or the e-mail address of the Google account in the case of Google authentication.
        role:
          $ref: '#/components/schemas/UserRoleModel'
        expiresAt:
          type: string
          description: Expiration time of the access token.
          format: date-time
        persistenceHint:
          enum:
          - Persistent
          - Ephemeral
          type: string
      additionalProperties: false
      example:
        tokenId: 0847312d-19fe-49d2-9e21-5825735b511a
        token: MtetyFcIW...xgXXX-Z4yy
    InvalidateAllAccessTokensRequestModel:
      type: object
      properties:
        invalidateCurrent:
          type: boolean
        tokenIds:
          type:
          - array
          - 'null'
          items:
            type: string
            format: uuid
      additionalProperties: false
    RequestPasswordResetRequestModel:
      required:
      - email
      type: object
      properties:
        email:
          minLength: 1
          type: string
          description: The e-mail address from the account which should have the password reset.
          format: email
      additionalProperties: false
    OAuthTokenResponseModel:
      type: object
      properties:
        access_token:
          type: string
          description: The access token to use to access the Verifiable API.
        token_type:
          type: string
          description: The OAuth 2.0 token type (ex. `Bearer`).
        expires_in:
          type: integer
          description: The number of seconds in which the access token will expire.
          format: int32
      additionalProperties: false
    GoogleAuthModel:
      type: object
      properties:
        code:
          type: string
          description: The authorization code returned by the Google Sign-In authentication flow.
        timeToLive:
          type: string
          description: If set, the created token will expire after the duration specified by this parameter. Note that the token will still be expired after 4 weeks of no use, regardless of the time to live. Additionally there might be a limit set for your organization. If the requested time-to-live exceeds this limit the token will be capped to that limit.
          format: timespan
        token:
          type: string
          description: The JWT token returned by Google Sign-In authentication flow.
      additionalProperties: false
      example:
        code: 4/yU4cQZT...4z7U4UmAI
        timeToLive: 00:30:00
    AccessTokenModel:
      type: object
      properties:
        id:
          type: string
          description: Unique identifier of the access token.
          format: uuid
        lastUserAgent:
          type: string
          description: The user agent of the remote user that last used this access token.
        lastIpAddress:
          type: string
          description: The IP address of the remote user that last used this access token.
        lastUsed:
          type: string
          description: The timestamp when this access token was last used.
          format: date-time
        isCurrent:
          type: boolean
          description: Set to true if this access token was used in the current request.
        expiresAt:
          type: string
          format: date-time
      additionalProperties: false
    UserRoleModel:
      type: object
      properties:
        id:
          type: string
          format: uuid
        name:
          enum:
          - Admin
          - LimitedAdmin
          - Credentialing
          - LimitedCredentialing
          - Reader
          - LimitedReader
          type: string
        permissions:
          type:
          - object
          - 'null'
          additionalProperties:
            enum:
            - None
            - Read
            - Write
            - Allowed
            type: string
      additionalProperties: false
    AccessTokenPageModel:
      type: object
      properties:
        sort:
          type: object
          properties:
            Keys:
              enum:
              - Id
              type: string
            Values:
              enum:
              - Asc
              - Desc
              type: string
          description: The properties and directions the data is sorted by.
        previousCursor:
          type: string
          description: The value to use for `cursor` to get to the previous paginated page. `null` will be returned if it's the first page.
        nextCursor:
          type: string
          description: The value to use for `cursor` to get to the next paginated page. `null` will be returned if it's the last page.
        nextOffset:
          type: integer
          description: The value to use for `offset` to get the next page following the current page or `null` if this page is the last.
          format: int32
          deprecated: true
        pageSize:
          type: integer
          description: The maximum number of items included in this page.
          format: int32
        count:
          type: integer
          description: The number of items in this page.
          format: int32
        totalCount:
          type: integer
          description: The total number of items in all pages combined.
          format: int32
        items:
          type: array
          items:
            $ref: '#/components/schemas/AccessTokenModel'
          description: The audit log entries in the current page.
        sortedBy:
          enum:
          - Id
          type: string
          description: The property by which the data is sorted.
        sortDirection:
          enum:
          - Asc
          - Desc
          type: string
          description: The direction in which the data is sorted.
      additionalProperties: false
      example:
        previousCursor: string
        nextCursor: string
        nextOffset: 0
        pageSize: 0
        count: 0
        totalCount: 0
        items:
        - id: 497f6eca-6276-4993-bfeb-53cbbbba6f08
          lastUserAgent: string
          lastIpAddress: string
          lastUsed: '2019-08-24T14:15:22.0000000Z'
          isCurrent: true
          expiresAt: '2019-08-24T14:15:22.0000000Z'
        sortedBy: Id
        sortDirection: Asc
        sort:
          Id: Asc
  securitySchemes:
    Bearer:
      type: http
      description: 'Enter your bearer token in the format: Bearer {your token}'
      scheme: bearer
      bearerFormat: custom
x-tagGroups:
- name: Authentication
  tags:
  - Authentication
- name: Definitions
  tags:
  - Definitions
- name: Providers
  tags:
  - Providers
  - ProvidersInfo
  - ProviderProfiles
  - Notes
  - Files
- name: Facilities
  tags:
  - Facilities
  - FacilitiesInfo
  - FacilitiesSpecialties
- name: Verifications
  tags:
  - Licenses
  - Datasets
  - DEA
  - BoardCertifications
- name: Monitoring
  tags:
  - Monitoring
  - Alerts
- name: Credentialing
  tags:
  - CredentialingRequests
- name: Integrations
  tags:
  - Integrations
  - Webhooks
- name: Audits
  tags:
  - Audit
- name: Account
  tags:
  - Users
- name: Organizations
  tags:
  - Reports
- name: Models
  tags:
  - Dataset Records
  - Webhook Callbacks