Pluralsight · Authentication Profile
Pluralsight Authentication
Authentication
Pluralsight secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
CoursesEducationEngineering MetricsLearningSkills AssessmentTechnologyVideo Training
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
bearerAuth http
scheme: bearer
Source
Authentication Profile
generated: '2026-08-29'
method: searched
source: openapi/pluralsight-coding-metrics-api-openapi.yml, openapi/pluralsight-collaboration-metrics-api-openapi.yml,
openapi/pluralsight-commits-api-openapi.yml, openapi/pluralsight-dora-metrics-api-openapi.yml,
openapi/pluralsight-graphql-api-openapi.yml, openapi/pluralsight-integrations-api-openapi.yml,
openapi/pluralsight-licensing-api-openapi.yml, openapi/pluralsight-pull-requests-api-openapi.yml,
openapi/pluralsight-reports-api-openapi.yml, openapi/pluralsight-repos-api-openapi.yml, openapi/pluralsight-teams-api-openapi.yml,
openapi/pluralsight-tickets-api-openapi.yml ...
summary:
types:
- http
schemes:
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: JWT
sources:
- openapi/pluralsight-coding-metrics-api-openapi.yml
- openapi/pluralsight-collaboration-metrics-api-openapi.yml
- openapi/pluralsight-commits-api-openapi.yml
- openapi/pluralsight-dora-metrics-api-openapi.yml
- openapi/pluralsight-graphql-api-openapi.yml
- openapi/pluralsight-integrations-api-openapi.yml
- openapi/pluralsight-licensing-api-openapi.yml
- openapi/pluralsight-pull-requests-api-openapi.yml
- openapi/pluralsight-reports-api-openapi.yml
- openapi/pluralsight-repos-api-openapi.yml
- openapi/pluralsight-teams-api-openapi.yml
- openapi/pluralsight-tickets-api-openapi.yml
- openapi/pluralsight-users-api-openapi.yml
docs: https://developer.pluralsight.com/manage-keys
searched: '2026-08-29'
searchedSources:
- https://developer.pluralsight.com/manage-keys
- https://developer.pluralsight.com/plan-permissions
- https://developer.pluralsight.com/docs/getting-started/faqs
- https://developer.pluralsight.com/docs/getting-started/release-stages
- https://mcp.pluralsight.com/.well-known/oauth-authorization-server
profiles:
- surface: Skills GraphQL API
endpoint: https://paas-api.pluralsight.com/graphql
type: apiKey
transport: bearer credential in the HTTP Authorization header
issuance: >-
A Pluralsight PLAN ADMIN mints the key on https://developer.pluralsight.com/manage-keys. A
non-admin cannot request one directly - they must ask a plan admin. Multiple keys per plan are
supported.
entitlement:
- >-
Plan level - whether the plan carries the API entitlement at all, visible on
https://developer.pluralsight.com/plan-permissions.
- >-
Key level - the release stage attached to the individual key (General Release / Beta / Alpha).
Beta is a self-serve toggle on the key; Alpha is by invitation from support@pluralsight.com.
scopes: []
scopes_note: >-
There are no scopes. A key carries whatever its plan carries; an agent cannot request a narrower
grant.
key_metadata:
- >-
Each key should carry an email address - that address is how Pluralsight sends deprecation
notices for operations the key is observed using.
unauthenticated_response: '401 {"error":"AuthenticationError: Invalid API Key"}'
observed: '2026-08-29'
- surface: MCP Gateway
endpoint: https://mcp.pluralsight.com/mcp
type: oauth2
flow: authorization_code
pkce: S256
dynamic_client_registration: https://mcp.pluralsight.com/register
authorization_endpoint: https://mcp.pluralsight.com/authorize
token_endpoint: https://mcp.pluralsight.com/token
jwks_uri: https://mcp.pluralsight.com/.well-known/jwks.json
token_endpoint_auth_methods_supported:
- none
scopes:
- invoke:gateway
- author:gateway
- employee:gateway
- admin:gateway
challenge: >-
401 with WWW-Authenticate: Bearer error="invalid_token",
resource_metadata="https://mcp.pluralsight.com/.well-known/oauth-protected-resource"
observed: '2026-08-29'
see_also: ../scopes/pluralsight-scopes.yml
note: >-
The bearerAuth/JWT scheme recorded in schemes[] above is what the OpenAPIs in this repo declare.
In practice the Skills API credential is a plan-admin API key presented as a bearer token, not a
JWT issued by an authorization server; the only true OAuth surface Pluralsight operates is the MCP
gateway.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pluralsight-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.