Stytch · Arazzo Workflow

Stytch OAuth Authenticate and Session

Version 1.0.0

Authenticate an OAuth token returned from a provider redirect and read the session.

1 workflow 2 source APIs 1 provider
View Spec View on GitHub AuthenticationIdentityPasswordlessSecurityB2BConnected AppsMCPAI AgentsDeveloper ToolsArazzoWorkflows

Provider

stytch

Workflows

oauth-authenticate-session
Authenticate an OAuth token and verify the resulting session.
Exchanges the OAuth token captured from a provider redirect for a session, then reads the active sessions for the resolved user.
2 steps inputs: session_duration_minutes, token outputs: providerType, sessionToken, userId
1
authenticateOauth
Authenticate the OAuth token to complete the social login, minting a session and resolving the user.
2
getSession
Read the active sessions for the authenticated user to confirm the OAuth login established a session.

Source API Descriptions

Arazzo Workflow Specification

Raw ↑
arazzo: 1.0.1
info:
  title: Stytch OAuth Authenticate and Session
  summary: Authenticate an OAuth token returned from a provider redirect and read the session.
  description: >-
    A social login completion flow for consumer apps. After the user returns
    from an OAuth provider redirect carrying a Stytch OAuth token, the workflow
    authenticates that token to mint a session and resolve the user, then reads
    the user's active sessions to confirm the login. Every step spells out its
    request inline so the flow can be read and executed without opening the
    underlying OpenAPI description. All calls authenticate with HTTP Basic auth
    using your Stytch project_id as the username and secret as the password.
  version: 1.0.0
  x-realizes-capability-ids:
  - BC-620.20
  x-capability-derivation:
    method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
    min_confidence: 0.7
    sources:
    - capability_id: BC-620.20
      capability_name: Identity & Access Management
      spec: stytch-session-api-openapi.yml
      confidence: 0.8
    model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: oauthApi
  url: ../openapi/stytch-oauth-api-openapi.yml
  type: openapi
- name: sessionApi
  url: ../openapi/stytch-session-api-openapi.yml
  type: openapi
workflows:
- workflowId: oauth-authenticate-session
  summary: Authenticate an OAuth token and verify the resulting session.
  description: >-
    Exchanges the OAuth token captured from a provider redirect for a session,
    then reads the active sessions for the resolved user.
  inputs:
    type: object
    required:
    - token
    properties:
      token:
        type: string
        description: The Stytch OAuth token returned on the provider redirect.
      session_duration_minutes:
        type: integer
        description: Optional session lifetime in minutes for the authenticated session.
  steps:
  - stepId: authenticateOauth
    description: >-
      Authenticate the OAuth token to complete the social login, minting a
      session and resolving the user.
    operationId: api_oauth_v1_Authenticate
    requestBody:
      contentType: application/json
      payload:
        token: $inputs.token
        session_duration_minutes: $inputs.session_duration_minutes
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      userId: $response.body#/user_id
      providerType: $response.body#/provider_type
      sessionToken: $response.body#/session_token
      sessionJwt: $response.body#/session_jwt
  - stepId: getSession
    description: >-
      Read the active sessions for the authenticated user to confirm the OAuth
      login established a session.
    operationId: api_session_v1_Get
    parameters:
    - name: user_id
      in: query
      value: $steps.authenticateOauth.outputs.userId
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      sessions: $response.body#/sessions
  outputs:
    userId: $steps.authenticateOauth.outputs.userId
    providerType: $steps.authenticateOauth.outputs.providerType
    sessionToken: $steps.authenticateOauth.outputs.sessionToken

Work with this as data

Every workflow here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for arazzo workflows

4 MCP tools reach this
  • find_arazzoBrowse and filter every workflow in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/stytch-oauth-authenticate-session-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.