Zitadel
Zitadel is an open source identity infrastructure platform providing secure authentication and user management with built-in support for OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, FIDO2, and passkeys. It offers multi-tenancy, fine-grained authorization, and a comprehensive management API for building and operating identity-first applications. Available as cloud-hosted and self-hosted deployments.
Zitadel publishes 7 APIs on the APIs.io network, including Applications API, Identity Providers API, Organizations API, and 4 more. Tagged areas include Authentication, Authorization, Identity Management, Open Source, and OAuth 2.0.
The Zitadel catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Zitadel’s developer surface includes authentication, engineering blog, documentation, tooling, signup flow, pricing, and 16 more developer resources.
Kin Score
APIs 11
Individual APIs this provider publishes, each with its own machine-readable definition.
Zitadel Auth API
The Zitadel Auth API provides endpoints for authenticated users to perform operations on their own accounts, including profile management, session handling, MFA setup, and perso...
Zitadel Admin API
The Zitadel Admin API provides instance-level configuration for Zitadel administrators. Used to configure instance-wide settings, default policies, SMTP, SMS providers, and mana...
Zitadel OIDC / OAuth 2.0
Zitadel implements the OpenID Connect and OAuth 2.0 standards for authentication and authorization flows. Provides authorization code flow, client credentials, device code, toke...
Zitadel SAML API
Zitadel provides SAML 2.0 single sign-on support, enabling enterprises to integrate with Zitadel using SAML identity federation. Accessible at /saml/v2/.
Zitadel Applications API
Manage OIDC, SAML, and API applications
Zitadel Identity Providers API
Manage external identity provider configurations
Zitadel Organizations API
Manage organizations and organizational domains
Zitadel Policies API
Manage login, password, and notification policies
Zitadel Projects API
Manage projects and project grants
Zitadel Roles API
Manage project roles and role grants
Zitadel Users API
Manage human and machine users
Scroll for all 11
Postman Collections 7
Ready-to-run Postman collections for exercising this provider's APIs.
Scroll for all 7
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Zitadel Management API
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Zitadel Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Zitadel Finops
FINOPSFeatures 7
Notable capabilities this provider offers.
Multi-Tenancy
Native multi-tenant architecture with organizations and projects.
OAuth 2.0 / OIDC
Standards-compliant OAuth 2.0 and OpenID Connect support.
SAML 2.0
Enterprise SAML 2.0 single sign-on for identity federation.
SCIM
SCIM-based user provisioning from upstream identity providers.
FIDO2 / Passkeys
Passwordless authentication with FIDO2 and passkeys.
MFA
Multi-factor authentication including TOTP, U2F, and FIDO2.
Self-Hosted or Cloud
Deploy as a managed cloud service or self-hosted on Kubernetes.
Scroll for all 7
Semantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Zitadel Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Zitadel API Rules
SPECTRALZitadel API Rules
SPECTRALJSON Schema 37
Standalone JSON Schema definitions for this provider's data models.
Application
JSON SCHEMAAppResponse
JSON SCHEMACreateApiAppRequest
JSON SCHEMACreateHumanUserRequest
JSON SCHEMACreateMachineUserRequest
JSON SCHEMACreateOidcAppRequest
JSON SCHEMACreateProjectRequest
JSON SCHEMACreateUserResponse
JSON SCHEMAError
JSON SCHEMAHumanEmail
JSON SCHEMAHumanPhone
JSON SCHEMAHumanProfile
JSON SCHEMAHumanUser
JSON SCHEMAListDetails
JSON SCHEMAListOrgsRequest
JSON SCHEMAListOrgsResponse
JSON SCHEMAListProjectsResponse
JSON SCHEMAListQuery
JSON SCHEMAListUsersRequest
JSON SCHEMAListUsersResponse
JSON SCHEMALoginPolicy
JSON SCHEMAMachineUser
JSON SCHEMAApplication
JSON SCHEMAHumanUser
JSON SCHEMAMachineUser
JSON SCHEMAObjectDetails
JSON SCHEMAOrganization
JSON SCHEMAProject
JSON SCHEMAUser
JSON SCHEMAMembership
JSON SCHEMAObjectDetails
JSON SCHEMAOrganization
JSON SCHEMAOrgResponse
JSON SCHEMAProject
JSON SCHEMAProjectResponse
JSON SCHEMAUser
JSON SCHEMAUserResponse
JSON SCHEMAScroll for all 37
JSON Structure 7
JSON Structure definitions describing this provider's data shapes.
Zitadel Management Application Structure
JSON STRUCTUREZitadel Management Human User Structure
JSON STRUCTUREZitadel Management Machine User Structure
JSON STRUCTUREZitadel Management Organization Structure
JSON STRUCTUREZitadel Management Project Structure
JSON STRUCTUREZitadel Management User Structure
JSON STRUCTUREZitadel Structure
JSON STRUCTUREScroll for all 7
Examples 4
Example request and response payloads for these APIs.
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 4
What developers build with this provider.
Customer Identity
B2C identity for customer-facing applications and portals.
Workforce Identity
B2B/B2E identity for employees, contractors, and partners.
Machine Identity
Service account identity and OAuth client credentials flow.
SaaS Multi-Tenancy
Tenant-isolated identity for multi-tenant SaaS applications.
Integrations 5
Pre-built integrations with other platforms and tools.
Terraform
Terraform provider for declarative Zitadel resource management.
Kubernetes
Helm charts for Zitadel deployment on Kubernetes.
Google Login
External identity provider integration with Google.
GitHub Login
External identity provider integration with GitHub.
SAML IdPs
Federation with SAML identity providers.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 3
Pagination, idempotency, versioning, errors, and events
Build 6
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Commercial 4
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API