Account
Who you are and how you got in: sign-in, the OAuth endpoints, your own identity, tier, key and usage (GET /auth/me works with an API key), and account deletion. Operations marked WEB SESSION ONLY need a person signed in at apis.io; an agent cannot call them with a key.
Start browser sign-in
BROWSER ONLY. Redirects a person to the chosen identity provider; the callback issues a Learn key and sets a web session. An agent cannot complete this — hand the URL to a person, or use the resolution.url a refusal carries.
query Parameters
providerAn id from GET /auth/providers.
Start browser sign-in › Responses
Redirect to the identity provider.
Who am I — identity, tier, key and usage
Works with an API key, a web session, or an AAuth-signed request. With a key it returns the account login, tier, principal_type: api_key, the masked key, and usage — the seven-day total and today (used, remaining and reset for the enforced daily window, from the gateway's own count). Its note says which operations need the signed-in web session instead. The answer to "which key am I using, what tier am I, and how much have I used".
Who am I — identity, tier, key and usage › Responses
The calling principal.
logintierprincipal_typekeyMasked.
noteOAuth 2.1 authorization endpoint
The authorization-code + PKCE (S256) entry point, as advertised in /.well-known/oauth-authorization-server. Redirects through browser sign-in. A self-registered client is granted apis:read only, whatever it requests; apis:pro and apis:business are granted only to a signed-in person on those plans.
OAuth 2.1 authorization endpoint › Responses
Redirect to sign-in or back to the client with a code.
OAuth dynamic client registration (RFC 7591)
Keyless. Registers a public client. A client registered this way is capped at apis:read and cannot unlock any gated resource on its own — paid tiers are reached by a signed-in person. The response carries a registration_access_token (shown once) and a registration_client_uri for RFC 7592 management. A client never exchanged for a token is removed after seven days. Registrations are capped per hour across all callers; the x-ratelimit-* headers report the remaining allowance, and 429 means retry after the reset.
OAuth dynamic client registration (RFC 7591) › Request Body
client_nameredirect_uristoken_endpoint_auth_methodOAuth dynamic client registration (RFC 7591) › Responses
The registered client, with registration_access_token and registration_client_uri.
Read a registered client (RFC 7592)
Authorized by the registration_access_token issued at registration, as a Bearer token. A wrong token and an unknown client both answer 401 invalid_token.
path Parameters
client_idRead a registered client (RFC 7592) › Responses
The client's current metadata and its registration_client_uri.
Update a registered client (RFC 7592)
Replaces the client's metadata. The body must carry the same client_id, may not set client_secret or registration_access_token, and is held to the same redirect_uri rules as registration. An update does not make an unused client permanent.
path Parameters
client_idUpdate a registered client (RFC 7592) › Responses
The updated metadata.

