# Logto

**Canonical:** https://apis.io/providers/logto/  
**Website:** https://logto.io  
**APIs profiled:** 39

Logto is an open source identity infrastructure platform with authentication, authorization, user management, and multi-tenancy supporting OIDC, OAuth, and SAML.

## Kin Score — 31.8 / 100 (thin)

Scored 2026-08-21 under rubric 0.12.0. Trend: flat (+0.0 from 31.8).

| Facet | Score |
|---|---|
| Discoverability | 63.0 |
| Contract Quality | 56.5 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 23.8 |
| Commercial Clarity | 15.8 |
| Access Clarity | 15.8 |

## Agent readiness — 32.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (39)

- **Logto Account center API** — Customize your account API settings.
- **Logto Applications API** — Application represents your registered software program or service that has been authorized to access user information and perform actions on behalf of users within the system. ...
- **Logto Audit logs API** — Audit logs are used to track end-user activities in Logto sign-in experience and other flows. It does not include activities in Logto Console.
- **Logto Authn API** — Authentication endpoints for third-party integrations and identity providers.
- **Logto Captcha provider API** — Setup the captcha provider.
- **Logto Configs API** — Endpoints for managing Logto global configurations for the tenant, such as admin console config and OIDC signing keys. See [🔑 Signing keys](https://docs.logto.io/docs/recipes/si...
- **Logto Connector factories API** — Connector factories are used to create connectors. They can be treated as preconfigured templates for connectors.
- **Logto Connectors API** — Connectors are the bridge between Logto and other third-party vendors who provide short message service (SMS), email service, or user information on wildly accepted social media...
- **Logto Custom phrases API** — Endpoints for managing custom phrases that allow you to customize the phrases displayed in the sign-in experience. See [Localized language](https://docs.logto.io/docs/recipes/cu...
- **Logto Custom profile fields API** — An admin feature used to create a customized user profile form, which is used to collect additional user information upon successful registrations.
- **Logto Dashboard API** — Endpoints that power the dashboard page of Console to show the statistics of the current tenant.
- **Logto Domains API** — Custom domain lets you present a consistent brand by having your own domain name on the sign-in and registration pages. See [🌍 Custom domain](https://docs.logto.io/docs/recipes/...
- **Logto Email templates API** — Manage custom i18n email templates for various types of emails, such as sign-in verification codes and password resets.
- **Logto Experience API** — The Experience endpoints allow end-users to interact with Logto for identity verification and profile completion.
- **Logto Hooks API** — Hook enables you to effortlessly receive real-time updates regarding specific events, such as user registration, sign-in, or password reset. See [🪝 Webhooks] to get started and ...
- **Logto My account API** — Account routes provide functionality for managing user profile for the end user to interact directly with access tokens.
- **Logto One-time tokens API** — One-time tokens are used for various authentication and verification purposes. They are typically sent via email and have an expiration time.
- **Logto Organization invitations API** — Organization invitations are used to invite users to join an organization. They are sent via email and contain a link that the user can click to accept the invitation and join t...
- **Logto Organization roles API** — Organization roles are used to define a set of organization scopes that can be assigned to users. Every organization role is a part of the organization template. Organization ro...
- **Logto Organization scopes API** — Organization scopes (permissions) are used to define actions that can be performed on a organization. Every organization scope is a part of the organization template. Organizati...
- **Logto Organizations API** — Organization is a concept that brings together multiple identities (mostly users). Logto supports multiple organizations, and each organization can have multiple users. Every or...
- **Logto Resources API** — Resources (API resources) represent the APIs that you want to protect with Logto. Each resource has a unique indicator (URI) and a set of scopes (permissions). The resources wil...
- **Logto Roles API** — Role management for API resource RBAC (role-based access control). See [🔐 Role-based access control (RBAC)](https://docs.logto.io/docs/recipes/rbac/) to get started with role-ba...
- **Logto SAML applications API** — SAML (Security Assertion Markup Language) applications represent applications that use SAML protocol for single sign-on (SSO). These endpoints allow you to manage SAML applicati...
- **Logto SAML applications auth flow API** — Endpoints for SAML (Security Assertion Markup Language) applications auth flow.
- **Logto Secrets API** — Secrets are used to store sensitive information such as API keys, third-party tokens, and other confidential data in Logto's Secret Vault.
- **Logto Sentinel activities API** — Sentinel activities are used to track and manage user authentication attempts, including successful and failed attempts. Based on your sentinel policy settings, Logto will autom...
- **Logto Sign-in experience API** — Endpoints for customizing Logto sign-in experience. See [🎨 Customize sign-in experience](https://docs.logto.io/docs/recipes/customize-sie/) to learn more about how the configura...
- **Logto SSO connector providers API** — Endpoints for SSO (single sign-on) connector providers. SSO connector providers provide the metadata and configuration templates for creating SSO connectors.
- **Logto SSO connectors API** — Endpoints for managing single sign-on (SSO) connectors. Your sign-in experience can use these well-configured SSO connectors to authenticate users and sync user attributes from ...
- **Logto Status API** — Endpoints for health check.
- **Logto Subject tokens API** — The subject token API provides the ability to create a new subject token for the use of impersonating the user.
- **Logto Swagger.json API** — Endpoints for the Swagger JSON document.
- **Logto Systems API** — Endpoints for system constants and information.
- **Logto User assets API** — Endpoints for managing user uploaded assets.
- **Logto Users API** — Endpoints for user management. Including creating, updating, deleting, and querying users with flexible filters. In addition to the endpoints, see [🧑‍🚀 Manage users](https://doc...
- **Logto Verification codes API** — Endpoints for handling verification codes. It is helpful when building a custom profile page in your app. See [👤 User profile](https://docs.logto.io/docs/recipes/user-profile/#o...
- **Logto Verifications API** — Endpoints for creating and validating verification records, which can be used in Profile routes.
- **Logto Well-known API** — Well-Known routes provide information and resources that can be discovered by clients without the need for authentication.

## Agentic access (1)

- **Logto Agentic Access** — 335 operations · 223 acting · 6 human-in-the-loop

## Security (2)

- **Logto Authentication** — oauth2 · 1 scheme
- **Logto Domain Security** — TLSv1.3 · DMARC

## Plans (1)

- **Logto Plans Pricing**

## Tags

Authentication, Authorization, Identity, OIDC, SAML, Open-Source

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/logto/). Scores are computed from the provider's own public artifacts under a published rubric.
