Apache Shiro
Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management. It provides a clean API for securing applications from the smallest mobile applications to the largest enterprise systems.
Apache Shiro publishes 5 APIs on the APIs.io network, including Authentication API, Authorization API, Cryptography API, and 2 more. Tagged areas include Authentication, Authorization, Cryptography, Java, and Security.
The Apache Shiro catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Apache Shiro’s developer surface includes documentation, engineering blog, and 7 more developer resources.
Kin Score
APIs 5
Individual APIs this provider publishes, each with its own machine-readable definition.
Apache Shiro Authentication API
The Authentication API from Apache Shiro — 3 operation(s) for authentication.
Apache Shiro Authorization API
The Authorization API from Apache Shiro — 2 operation(s) for authorization.
Apache Shiro Cryptography API
The Cryptography API from Apache Shiro — 1 operation(s) for cryptography.
Apache Shiro Sessions API
The Sessions API from Apache Shiro — 1 operation(s) for sessions.
Apache Shiro Users API
The Users API from Apache Shiro — 1 operation(s) for users.
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Apache Shiro Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Apache Shiro Finops
FINOPSFeatures 7
Notable capabilities this provider offers.
Authentication
Pluggable authentication with username/password, remember-me, and token support
Authorization
Role-based and permission-based access control with wildcard permissions
Session Management
Native session management independent of HTTP containers
Cryptography
Password hashing with salt, bcrypt, Argon2, and SHA-256
Multiple Realms
JDBC, LDAP, properties file, and custom realm support
Web Integration
Filter-based web application security with URL pattern matching
Annotations
AOP and annotation-based security for method-level authorization
Scroll for all 7
Semantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Apache Shiro Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Apache Shiro API Rules
SPECTRALApache Shiro API Rules
SPECTRALJSON Schema 12
Standalone JSON Schema definitions for this provider's data models.
HashRequest
JSON SCHEMAHashResult
JSON SCHEMALoginRequest
JSON SCHEMALoginResponse
JSON SCHEMAPermissionCheckRequest
JSON SCHEMAPermissionCheckResult
JSON SCHEMARoleList
JSON SCHEMASession
JSON SCHEMATokenResponse
JSON SCHEMAUserList
JSON SCHEMAUserRequest
JSON SCHEMAUser
JSON SCHEMAScroll for all 12
JSON Structure 12
JSON Structure definitions describing this provider's data shapes.
Apache Shiro Hash Request Structure
JSON STRUCTUREApache Shiro Hash Result Structure
JSON STRUCTUREApache Shiro Login Request Structure
JSON STRUCTUREApache Shiro Login Response Structure
JSON STRUCTUREApache Shiro Permission Check Request Structure
JSON STRUCTUREApache Shiro Permission Check Result Structure
JSON STRUCTUREApache Shiro Role List Structure
JSON STRUCTUREApache Shiro Session Structure
JSON STRUCTUREApache Shiro Token Response Structure
JSON STRUCTUREApache Shiro User List Structure
JSON STRUCTUREApache Shiro User Request Structure
JSON STRUCTUREApache Shiro User Structure
JSON STRUCTUREScroll for all 12
Examples 12
Example request and response payloads for these APIs.
Apache Shiro Session Example
EXAMPLEApache Shiro User Example
EXAMPLEScroll for all 12
Security Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 4
What developers build with this provider.
Web Application Security
Secure Java web applications with authentication and URL-based access control
REST API Security
Protect REST APIs with token authentication and permission checks
Microservice Auth
Stateless JWT authentication for microservice architectures
Admin Portal Security
Role-based admin interface with fine-grained permissions
Integrations 5
Pre-built integrations with other platforms and tools.
Spring Framework
Shiro Spring integration for bean-level security
Jakarta EE
Java EE web filter integration for servlet containers
LDAP/Active Directory
LDAP realm for enterprise user directory authentication
JDBC
Database-backed realm for user and permission storage
Hazelcast
Distributed session management with Hazelcast
Resources
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 3
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Company 1
The organization behind the API