Kinde · OpenAPI Overlay 1.0.0

API Evangelist enhancements for the Kinde Account API

2 actions 2 updates servers
Generated by API Evangelist Written by API Evangelist tooling for Kinde's API. It is a proposal applied on top of the contract, not a document Kinde publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

serversx-audiencex-auth-notex-oidc-discoveryx-endpointsx-apievangelist-artifacts

Targets 2

$
$.info

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for the Kinde Account API
  version: 1.0.0
  x-generated: '2026-09-12'
  x-method: generated
  x-source: >-
    Generated from artifacts in this repo plus the OIDC discovery document probed at
    https://app.kinde.com/.well-known/openid-configuration (HTTP 200, 2026-09-12).
  x-extends: openapi/_original/kinde-frontend-api-openapi.yml
  x-rationale: >-
    The published Account API spec (info.title "Kinde Account API") declares NO servers[] block at
    all. Its paths are rooted at /account_api/v1/ and /oauth2/, and the host is the caller's own
    Kinde tenant. This overlay records that host as a templated server rather than leaving the
    contract with no base URL, and records the OIDC scopes the discovery document advertises.
actions:
  - target: $
    description: >-
      Supply the templated tenant server the spec omits. The host is documented throughout
      Kinde's docs as https://{subdomain}.kinde.com and is the same issuer as the OAuth endpoints
      this spec already contains.
    update:
      servers:
        - url: https://{subdomain}.kinde.com
          description: >-
            The caller's own Kinde business subdomain. Templated because Kinde is
            tenant-per-subdomain; there is no shared host.
          variables:
            subdomain:
              default: your_kinde_subdomain
              description: The subdomain generated for your business on Kinde.
  - target: $.info
    description: Record the end-user auth model and the OIDC scopes advertised in discovery.
    update:
      x-audience: end-user
      x-auth-note: >-
        Operations resolve relative to the SUBJECT of the bearer token. This API acts as the
        signed-in user and cannot read another user, which is what makes it safe to call from a
        user-facing surface. An M2M token is not valid here.
      x-oidc-discovery:
        url: https://app.kinde.com/.well-known/openid-configuration
        probed: '2026-09-12'
        http_status: 200
        saved: well-known/kinde-app-openid-configuration.json
        id_token_signing_alg_values_supported: [RS256]
        code_challenge_methods_supported: [S256]
        response_types_supported: [code]
        scopes_supported: [address, email, event_hooks, offline, openid, phone, profile]
      x-endpoints:
        authorization: https://{subdomain}.kinde.com/oauth2/auth
        token: https://{subdomain}.kinde.com/oauth2/token
        userinfo: https://{subdomain}.kinde.com/oauth2/v2/user_profile
        introspection: https://{subdomain}.kinde.com/oauth2/introspect
        revocation: https://{subdomain}.kinde.com/oauth2/revoke
        end_session: https://{subdomain}.kinde.com/logout
        jwks: https://{subdomain}.kinde.com/.well-known/jwks
      x-apievangelist-artifacts:
        conventions: conventions/kinde-conventions.yml
        components: components/kinde-components.yml
        skills: skills/kinde-end-user-self-serve-portal.md