Apache Shiro website screenshot

Apache Shiro

Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management. It provides a clean API for securing applications from the smallest mobile applications to the largest enterprise systems.

Apache Shiro publishes 5 APIs on the APIs.io network, including Authentication API, Authorization API, Cryptography API, and 2 more. Tagged areas include Authentication, Authorization, Cryptography, Java, and Security.

The Apache Shiro catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Apache Shiro’s developer surface includes documentation, engineering blog, and 8 more developer resources.

28.7/100 thin ▬ flat Agent 17/100 agent aware Full breakdown ↓
scored 2026-09-10 · rubric v0.20.0
AccessFreemium
1 APIs 7 Features 4 Use Cases
AuthenticationAuthorizationCryptographyJavaSecurityApacheOpen-Source

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-10 · rubric v0.20.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/apache-shiro: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Apache Shiro Authentication API

The Authentication API from Apache Shiro — 3 operation(s) for authentication.

Apache Shiro Authorization API

The Authorization API from Apache Shiro — 2 operation(s) for authorization.

Apache Shiro Cryptography API

The Cryptography API from Apache Shiro — 1 operation(s) for cryptography.

Apache Shiro Sessions API

The Sessions API from Apache Shiro — 1 operation(s) for sessions.

Apache Shiro Users API

The Users API from Apache Shiro — 1 operation(s) for users.

Open Collections 6

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Apache Shiro Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 7

Notable capabilities this provider offers.

Authentication

Pluggable authentication with username/password, remember-me, and token support

Authorization

Role-based and permission-based access control with wildcard permissions

Session Management

Native session management independent of HTTP containers

Cryptography

Password hashing with salt, bcrypt, Argon2, and SHA-256

Multiple Realms

JDBC, LDAP, properties file, and custom realm support

Web Integration

Filter-based web application security with URL pattern matching

Annotations

AOP and annotation-based security for method-level authorization

Scroll for all 7

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Apache Shiro Context

12 classes · 26 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Apache Shiro API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Apache Shiro API Rules

12 rules · 5 errors 6 warnings 1 info

SPECTRAL

JSON Schema 12

Standalone JSON Schema definitions for this provider's data models.

HashRequest

3 properties

JSON SCHEMA

HashResult

4 properties

JSON SCHEMA

LoginRequest

3 properties

JSON SCHEMA

LoginResponse

4 properties

JSON SCHEMA

PermissionCheckRequest

1 properties

JSON SCHEMA

PermissionCheckResult

3 properties

JSON SCHEMA

RoleList

2 properties

JSON SCHEMA

Session

6 properties

JSON SCHEMA

TokenResponse

4 properties

JSON SCHEMA

UserList

2 properties

JSON SCHEMA

UserRequest

4 properties

JSON SCHEMA

User

5 properties

JSON SCHEMA

Scroll for all 12

JSON Structure 12

JSON Structure definitions describing this provider's data shapes.

Apache Shiro Hash Request Structure

3 properties

JSON STRUCTURE

Apache Shiro Hash Result Structure

4 properties

JSON STRUCTURE

Apache Shiro Login Request Structure

3 properties

JSON STRUCTURE

Apache Shiro Login Response Structure

4 properties

JSON STRUCTURE

Apache Shiro Role List Structure

2 properties

JSON STRUCTURE

Apache Shiro Session Structure

6 properties

JSON STRUCTURE

Apache Shiro Token Response Structure

4 properties

JSON STRUCTURE

Apache Shiro User List Structure

2 properties

JSON STRUCTURE

Apache Shiro User Request Structure

4 properties

JSON STRUCTURE

Apache Shiro User Structure

5 properties

JSON STRUCTURE

Scroll for all 12

Examples 12

Example request and response payloads for these APIs.

Apache Shiro User Example

5 fields

EXAMPLE

Scroll for all 12

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Apache Shiro Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Apache Shiro Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Apache Shiro Agentic Access

10 operations · 7 acting

10 operations · 7 acting

AGENTIC

Use Cases 4

What developers build with this provider.

Web Application Security

Secure Java web applications with authentication and URL-based access control

REST API Security

Protect REST APIs with token authentication and permission checks

Microservice Auth

Stateless JWT authentication for microservice architectures

Admin Portal Security

Role-based admin interface with fine-grained permissions

Integrations 5

Pre-built integrations with other platforms and tools.

Spring Framework

Shiro Spring integration for bean-level security

Jakarta EE

Java EE web filter integration for servlet containers

LDAP/Active Directory

LDAP realm for enterprise user directory authentication

JDBC

Database-backed realm for user and permission storage

Hazelcast

Distributed session management with Hazelcast

Resources

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: apache-shiro
name: Apache Shiro
description: Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization,
  cryptography, and session management. It provides a clean API for securing applications from the smallest mobile applications
  to the largest enterprise systems.
type: Index
deliveryModel:
  model: unknown
  open_source: false
  commercial: false
  callable_host: false
  label: Delivery model not determined — needs a product licence on record
  confidence: low
  source:
  - openapi
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Freemium
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
position: Consuming
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/apache-shiro.png
tags:
- Authentication
- Authorization
- Cryptography
- Java
- Security
- Apache
- Open-Source
tags_raw:
- Authentication
- Authorization
- Cryptography
- Java
- Security
- Apache
- Open Source
created: '2026-03-16'
modified: '2026-05-19'
url: https://raw.githubusercontent.com/api-evangelist/apache-shiro/refs/heads/main/apis.yml
specificationVersion: '0.23'
apis:
- aid: apache-shiro:apache-shiro-authentication-api
  name: Apache Shiro Authentication API
  description: The Authentication API from Apache Shiro — 3 operation(s) for authentication.
  humanURL: https://shiro.apache.org/documentation.html
  tags:
  - Authentication
  properties:
  - type: OpenAPI
    url: openapi/apache-shiro-authentication-api-openapi.yml
  - type: Documentation
    url: https://shiro.apache.org/documentation.html
- aid: apache-shiro:apache-shiro-authorization-api
  name: Apache Shiro Authorization API
  description: The Authorization API from Apache Shiro — 2 operation(s) for authorization.
  humanURL: https://shiro.apache.org/documentation.html
  tags:
  - Authorization
  properties:
  - type: OpenAPI
    url: openapi/apache-shiro-authorization-api-openapi.yml
  - type: Documentation
    url: https://shiro.apache.org/documentation.html
- aid: apache-shiro:apache-shiro-cryptography-api
  name: Apache Shiro Cryptography API
  description: The Cryptography API from Apache Shiro — 1 operation(s) for cryptography.
  humanURL: https://shiro.apache.org/documentation.html
  tags:
  - Cryptography
  properties:
  - type: OpenAPI
    url: openapi/apache-shiro-cryptography-api-openapi.yml
  - type: Documentation
    url: https://shiro.apache.org/documentation.html
- aid: apache-shiro:apache-shiro-sessions-api
  name: Apache Shiro Sessions API
  description: The Sessions API from Apache Shiro — 1 operation(s) for sessions.
  humanURL: https://shiro.apache.org/documentation.html
  tags:
  - Sessions
  properties:
  - type: OpenAPI
    url: openapi/apache-shiro-sessions-api-openapi.yml
  - type: Documentation
    url: https://shiro.apache.org/documentation.html
- aid: apache-shiro:apache-shiro-users-api
  name: Apache Shiro Users API
  description: The Users API from Apache Shiro — 1 operation(s) for users.
  humanURL: https://shiro.apache.org/documentation.html
  tags:
  - User
  tags_raw:
  - Users
  properties:
  - type: OpenAPI
    url: openapi/apache-shiro-users-api-openapi.yml
  - type: Documentation
    url: https://shiro.apache.org/documentation.html
maintainers:
- FN: Kin Lane
  email: info@apievangelist.com
common:
- type: Website
  url: https://www.apache.org/
- type: AgenticAccess
  url: agentic-access/apache-shiro-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/apache-shiro-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/apache-shiro-domain-security.yml
- type: GitHubOrganization
  url: https://github.com/apache/shiro
- type: Documentation
  url: https://shiro.apache.org/
- type: SpectralRules
  url: rules/apache-shiro-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/apache-shiro-vocabulary.yaml
- type: JSONLD
  url: json-ld/apache-shiro-context.jsonld
- type: Features
  data:
  - name: Authentication
    description: Pluggable authentication with username/password, remember-me, and token support
  - name: Authorization
    description: Role-based and permission-based access control with wildcard permissions
  - name: Session Management
    description: Native session management independent of HTTP containers
  - name: Cryptography
    description: Password hashing with salt, bcrypt, Argon2, and SHA-256
  - name: Multiple Realms
    description: JDBC, LDAP, properties file, and custom realm support
  - name: Web Integration
    description: Filter-based web application security with URL pattern matching
  - name: Annotations
    description: AOP and annotation-based security for method-level authorization
- type: UseCases
  data:
  - name: Web Application Security
    description: Secure Java web applications with authentication and URL-based access control
  - name: REST API Security
    description: Protect REST APIs with token authentication and permission checks
  - name: Microservice Auth
    description: Stateless JWT authentication for microservice architectures
  - name: Admin Portal Security
    description: Role-based admin interface with fine-grained permissions
- type: Integrations
  data:
  - name: Spring Framework
    description: Shiro Spring integration for bean-level security
  - name: Jakarta EE
    description: Java EE web filter integration for servlet containers
  - name: LDAP/Active Directory
    description: LDAP realm for enterprise user directory authentication
  - name: JDBC
    description: Database-backed realm for user and permission storage
  - name: Hazelcast
    description: Distributed session management with Hazelcast
- type: Blog
  url: https://shiro.apache.org/news

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/apache-shiro"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/apache-shiro/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/apache-shiro/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.