# Authsignal

**Canonical:** https://apis.io/providers/authsignal/  
**Website:** https://www.authsignal.com/  
**APIs profiled:** 22

Authsignal is a passwordless, step-up, and risk-based authentication platform. The product wraps passkeys, authenticator apps (TOTP), SMS and WhatsApp OTP, email OTP and magic links, push notifications, biometrics (face / palm), and ID verification behind a unified Server API, Client API, and Management API. A no-code rules engine routes high-risk events through step-up challenges, and audit / observability surfaces every authentication attempt. Authsignal slots in front of existing identity providers (Cognito, Auth0, Azure AD B2C, Keycloak, IdentityServer, NextAuth.js) or works standalone.

## Kin Score — 39.7 / 100 (developing)

Scored 2026-08-21 under rubric 0.12.0. Trend: flat (+0.0 from 39.7).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 53.5 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 23.8 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 29.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Free · Self-serve signup — onboarding: self-serve, pricing: free, trial: no (confidence: high).

## APIs (22)

- **Authsignal Server API** — Server-to-server REST API used to track user actions, evaluate the rules engine, mint short-lived URLs for the pre-built authentication UI, issue client tokens, validate challen...
- **Authsignal Client API** — Browser / device-facing REST API for fully custom authentication UIs. Supports passkeys, authenticator apps, SMS / WhatsApp OTP, email OTP, magic links, and push challenges. Aut...
- **Authsignal Management API** — REST API for tenant-level configuration: actions and rules, theme and branding, and other tenant settings. Authenticated with a separate management API key.
- **Authsignal Webhooks** — Outbound webhooks delivering authentication and enrollment events, enabling downstream systems to react to user lifecycle changes and challenge outcomes.
- **Authsignal Node.js SDK** — Official server-side SDK for Node.js / TypeScript wrapping the Server API.
- **Authsignal Python SDK** — Official server-side Python SDK for the Authsignal Server API.
- **Authsignal Java SDK** — Official Java / Kotlin SDK for the Authsignal Server API.
- **Authsignal .NET SDK** — Official C# / .NET SDK for the Authsignal Server API.
- **Authsignal Ruby SDK** — Official Ruby SDK for the Authsignal Server API.
- **Authsignal PHP SDK** — Official PHP SDK for the Authsignal Server API.
- **Authsignal Go SDK** — Official Go SDK for the Authsignal Server API.
- **Authsignal Browser SDK** — JavaScript / TypeScript browser SDK wrapping the Client API and WebAuthn / passkey ceremonies for web applications.
- **Authsignal iOS SDK** — Native iOS (Swift) SDK for passkeys, push, and OTP challenges in iOS applications.
- **Authsignal Android SDK** — Native Android (Kotlin) SDK for passkeys, push, and OTP challenges in Android applications.
- **Authsignal React Native SDK** — React Native wrapper around the iOS and Android SDKs.
- **Authsignal Flutter SDK** — Flutter (Dart) SDK wrapping the iOS and Android native SDKs.
- **Authsignal Actions API** — The Actions API from Authsignal — 3 operation(s) for actions.
- **Authsignal Authenticators API** — The Authenticators API from Authsignal — 4 operation(s) for authenticators.
- **Authsignal Challenges API** — The Challenges API from Authsignal — 5 operation(s) for challenges.
- **Authsignal Devices API** — The Devices API from Authsignal — 3 operation(s) for devices.
- **Authsignal Sessions API** — The Sessions API from Authsignal — 5 operation(s) for sessions.
- **Authsignal Users API** — The Users API from Authsignal — 2 operation(s) for users.

## Agentic access (1)

- **Authsignal Agentic Access** — 26 operations · 18 acting · 2 human-in-the-loop

## Security (2)

- **Authsignal Authentication** — http · 1 scheme
- **Authsignal Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Authsignal Plans Pricing**

## Tags

Authentication, Passkeys, MFA, Step-Up, Passwordless, Risk, Biometrics, Identity Verification

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/authsignal/). Scores are computed from the provider's own public artifacts under a published rubric.
