# Authlete

**Canonical:** https://apis.io/providers/authlete/  
**Website:** https://authlete.com  
**APIs profiled:** 1

Authlete is an API-first OAuth 2.0 and OpenID Connect backend service that provides a headless authorization-server engine. It handles the OAuth/OIDC protocol logic and token management so organizations can stand up standards-compliant authorization servers and verifiable-credential issuers without building the protocol layer themselves. Authlete separates the Management APIs (configure services and clients) from the Runtime APIs (power authorization, token, introspection, CIBA, device-flow, federation, and OID4VCI endpoints), and offers managed shared cloud, dedicated cloud, and self-managed deployment across US, Japan, Europe, and Brazil regional clusters. It supports advanced profiles including FAPI / FAPI 2.0, CIBA, PAR, Grant Management, OpenID Federation, Native SSO, and OpenID for Verifiable Credential Issuance, plus regional open-banking standards (Brazil Open Banking, Australia CDR). Backed by 500 Global.

## Kin Score — 48.9 / 100 (developing)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (-0.6 from 49.5).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 55.8 |
| Governance | 4.5 |
| Contract Governance | 4.5 |
| Operational Transparency | 52.6 |
| Developer Ergonomics | 68.5 |
| Commercial Clarity | 31.6 |
| Access Clarity | 31.6 |

## Agent readiness — 26.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (21)

- **Authlete Authorization Endpoint API** — API endpoints for implementing OAuth 2.0 Authorization Endpoint.
- **Authlete CIBA API** — API endpoints for implementing Client-Initiated Backchannel Authentication (CIBA).
- **Authlete Client Management API** — API endpoints for managing OAuth clients, including creation, update, and deletion of clients.
- **Authlete Device Flow API** — API endpoints for implementing OAuth 2.0 Device Flow
- **Authlete Dynamic Client Registration API** — API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
- **Authlete Federation Endpoint API** — API endpoints for implementing OpenID Federation using Authlete.
- **Authlete Grant Management Endpoint API** — API endpoint for implementing OAuth 2.0 grants, including grant management actions like updating and revoking grants.
- **Authlete Hardware Security Key API** — API endpoints for managing hardware security keys (HSK).
- **Authlete Introspection Endpoint API** — API endpoints for implementing OAuth 2.0 Introspection Endpoint.
- **Authlete Jose Object API** — API endpoints for JOSE objects.
- **Authlete JWK Set Endpoint API** — API endpoints for to generate JSON Web Key Set (JWKS) for a service.
- **Authlete Lifecycle API** — The Lifecycle API from Authlete — 1 operation(s) for lifecycle.
- **Authlete Native SSO API** — API endpoints for Native SSO
- **Authlete Pushed Authorization Endpoint API** — API endpoints for implementing OAuth 2.0 Pushed Authorization Requests (PAR).
- **Authlete Revocation Endpoint API** — API endpoint for implementing OAuth 2.0 Revocation Endpoint.
- **Authlete Service Management API** — API endpoints for managing services, including creation, update, and deletion of services.
- **Authlete Token Endpoint API** — API endpoints for implementing OAuth 2.0 Token Endpoint.
- **Authlete Token Operations API** — API endpoints for various token related operations, including creating, revoking and deleting access_tokens with specified scopes.
- **Authlete UserInfo Endpoint API** — API endpoints for implementing OpenID Connect UserInfo Endpoint.
- **Authlete Utility Endpoints API** — API endpoints for various utility operations.
- **Authlete Verifiable Credential Issuer API** — API endpoints for implementing and running a Verifiable Credential Issuer (VCI).

## MCP servers (1)

- **Authlete MCP Server** — No official hosted/remote Authlete MCP server was found (no @authlete MCP package, no registry listing, no docs reference as of this pass). This is a DERIVED candidate tool list...

## Agentic access (1)

- **Authlete Agentic Access** — 86 operations · 68 acting · 1 human-in-the-loop

## Security (3)

- **Authlete Authentication** — http · 1 scheme
- **Authlete Domain Security** — TLSv1.3 · DMARC
- **Authlete Vulnerability Disclosure** — security.txt · contact published

## Tags

Company, Authentication, OpenID Connect, Authorization, Identity, API Security, FAPI, Verifiable Credentials, CIBA

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/authlete/). Scores are computed from the provider's own public artifacts under a published rubric.
