API endpoints
Every route of the Pocket ID REST API on one page, grouped by resource, with its parameters, request body and response fields.
Every route of the REST API, with the parameters it takes and the fields it answers with. The page comes from the backend's spec at every docs build, so it lists what the code serves.
Send an API key in the X-API-KEY header with each call. REST API covers creating keys and the shape of errors. The raw spec is available as swagger.json and swagger.yaml for Postman, code generators and AI assistants.
Users, their passkeys and profile pictures, login codes and signup tokens.
- post
/api/one-time-access-emailRequest one-time access email - post
/api/one-time-access-token/{token}Exchange one-time access token - post
/api/signupSign up - get
/api/signup-tokensList signup tokens - post
/api/signup-tokensCreate signup token - delete
/api/signup-tokens/{id}Delete signup token - post
/api/signup/setupSign up initial admin user - get
/api/usersList users - post
/api/usersCreate user - get
/api/users/meGet current user - put
/api/users/meUpdate current user - put
/api/users/me/profile-pictureUpdate current user's profile picture - delete
/api/users/me/profile-pictureReset current user's profile picture - post
/api/users/me/send-email-verificationSend email verification - post
/api/users/me/verify-emailVerify email - get
/api/users/{id}Get user by ID - put
/api/users/{id}Update user - delete
/api/users/{id}Delete user - get
/api/users/{id}/groupsGet user groups - post
/api/users/{id}/one-time-access-emailRequest one-time access email (admin) - post
/api/users/{id}/one-time-access-tokenCreate one-time access token for user (admin) - put
/api/users/{id}/profile-pictureUpdate user profile picture - delete
/api/users/{id}/profile-pictureReset user profile picture - get
/api/users/{id}/profile-picture.pngGet user profile picture - put
/api/users/{id}/user-groupsUpdate user groups - get
/api/users/{id}/webauthn-credentialsList user passkeys - delete
/api/users/{id}/webauthn-credentials/{credentialId}Delete user passkey
Request one-time access email
Section titled “Request one-time access email”/api/one-time-access-emailRequest a one-time access email for unauthenticated users
Body application/json
emailstringrequiredredirectPathstring
Response
Exchange one-time access token
Section titled “Exchange one-time access token”/api/one-time-access-token/{token}Exchange a one-time access token for a session token
Path parameters
tokenstringrequiredOne-time access token
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Sign up
Section titled “Sign up”/api/signupCreate a new user account
Body application/json
usernamestringrequired1 to 50 characters
emailstringfirstNamestringat most 50 characters
lastNamestringat most 50 characters
tokenstring
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
List signup tokens
Section titled “List signup tokens”/api/signup-tokensGet a paginated list of signup tokens
Query parameters
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects7 fields per item
createdAtstringexpiresAtstringidstringtokenstringusageCountintegerusageLimitintegeruserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Create signup token
Section titled “Create signup token”/api/signup-tokensCreate a new signup token that allows user registration
Body application/json
ttlobjectrequiredusageLimitintegerrequired1 to 100
userGroupIdsarray of strings
Response
7 fields
createdAtstringexpiresAtstringidstringtokenstringusageCountintegerusageLimitintegeruserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
Delete signup token
Section titled “Delete signup token”/api/signup-tokens/{id}Delete a signup token by ID
Path parameters
idstringrequiredToken ID
Response
Sign up initial admin user
Section titled “Sign up initial admin user”/api/signup/setupSign up and generate setup access token for initial admin user
Body application/json
usernamestringrequired1 to 50 characters
emailstringfirstNamestringat most 50 characters
lastNamestringat most 50 characters
tokenstring
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
List users
Section titled “List users”/api/usersGet a paginated list of users with optional search and sorting
Query parameters
searchstringSearch term to filter users
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects13 fields per item
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Create user
Section titled “Create user”/api/usersCreate a new user
Body application/json
usernamestringrequired1 to 50 characters
disabledbooleandisplayNamestringat most 100 characters
emailstringemailVerifiedbooleanfirstNamestringat most 50 characters
idstringisAdminbooleanlastNamestringat most 50 characters
localestringuserGroupIdsarray of strings
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Get current user
Section titled “Get current user”/api/users/meRetrieve information about the currently authenticated user
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Update current user
Section titled “Update current user”/api/users/meUpdate the currently authenticated user's information
Body application/json
usernamestringrequired1 to 50 characters
disabledbooleandisplayNamestringat most 100 characters
emailstringemailVerifiedbooleanfirstNamestringat most 50 characters
idstringisAdminbooleanlastNamestringat most 50 characters
localestringuserGroupIdsarray of strings
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Update current user's profile picture
Section titled “Update current user's profile picture”/api/users/me/profile-pictureUpdate the currently authenticated user's profile picture
Body multipart/form-data
filebinaryrequiredProfile picture image file (PNG, JPG, or JPEG)
Response
Reset current user's profile picture
Section titled “Reset current user's profile picture”/api/users/me/profile-pictureReset the currently authenticated user's profile picture to the default
Response
Send email verification
Section titled “Send email verification”/api/users/me/send-email-verificationSend an email verification to the currently authenticated user
Response
Verify email
Section titled “Verify email”/api/users/me/verify-emailVerify the currently authenticated user's email using a verification token
Body application/json
tokenstringrequired
Response
Get user by ID
Section titled “Get user by ID”/api/users/{id}Retrieve detailed information about a specific user
Path parameters
idstringrequiredUser ID
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Update user
Section titled “Update user”/api/users/{id}Update an existing user by ID
Path parameters
idstringrequiredUser ID
Body application/json
usernamestringrequired1 to 50 characters
disabledbooleandisplayNamestringat most 100 characters
emailstringemailVerifiedbooleanfirstNamestringat most 50 characters
idstringisAdminbooleanlastNamestringat most 50 characters
localestringuserGroupIdsarray of strings
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Delete user
Section titled “Delete user”/api/users/{id}Delete a specific user by ID
Path parameters
idstringrequiredUser ID
Response
Get user groups
Section titled “Get user groups”/api/users/{id}/groupsRetrieve all groups a specific user belongs to
Path parameters
idstringrequiredUser ID
Response
8 fields per item
allowedOidcClientsarray of objects8 fields per item
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringusersarray of objects13 fields per item
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Request one-time access email (admin)
Section titled “Request one-time access email (admin)”/api/users/{id}/one-time-access-emailRequest a one-time access email for a specific user (admin only)
Path parameters
idstringrequiredUser ID
Body application/json
ttlobject
Response
Create one-time access token for user (admin)
Section titled “Create one-time access token for user (admin)”/api/users/{id}/one-time-access-tokenGenerate a one-time access token for a specific user (admin only)
Path parameters
idstringrequiredUser ID
Body application/json
object
Response
Update user profile picture
Section titled “Update user profile picture”/api/users/{id}/profile-pictureUpdate a specific user's profile picture
Path parameters
idstringrequiredUser ID
Body multipart/form-data
filebinaryrequiredProfile picture image file (PNG, JPG, or JPEG)
Response
Reset user profile picture
Section titled “Reset user profile picture”/api/users/{id}/profile-pictureReset a specific user's profile picture to the default
Path parameters
idstringrequiredUser ID
Response
Get user profile picture
Section titled “Get user profile picture”/api/users/{id}/profile-picture.pngRetrieve a specific user's profile picture
Path parameters
idstringrequiredUser ID
Response
Update user groups
Section titled “Update user groups”/api/users/{id}/user-groupsUpdate the groups a specific user belongs to
Path parameters
idstringrequiredUser ID
Body application/json
userGroupIdsarray of stringsrequired
Response
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
List user passkeys
Section titled “List user passkeys”/api/users/{id}/webauthn-credentialsRetrieve all WebAuthn credentials for a specific user
Path parameters
idstringrequiredUser ID
Response
10 fields per item
aaguidstringattestationTypestringbackupEligiblebooleanbackupStatebooleancreatedAtstringcredentialIDstringhasIconbooleanidstringnamestringtransportarray of strings
Delete user passkey
Section titled “Delete user passkey”/api/users/{id}/webauthn-credentials/{credentialId}Delete a specific WebAuthn credential for a user
Path parameters
idstringrequiredUser ID
credentialIdstringrequiredCredential ID
Response
User Groups
Section titled “User Groups”Groups and their members.
- get
/api/user-groupsList user groups - post
/api/user-groupsCreate user group - get
/api/user-groups/{id}Get user group by ID - put
/api/user-groups/{id}Update user group - delete
/api/user-groups/{id}Delete user group - put
/api/user-groups/{id}/usersUpdate users in a group
List user groups
Section titled “List user groups”/api/user-groupsGet a paginated list of user groups with optional search and sorting
Query parameters
searchstringSearch term to filter user groups by name
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Create user group
Section titled “Create user group”/api/user-groupsCreate a new user group
Body application/json
friendlyNamestringrequired2 to 50 characters
namestringrequired2 to 255 characters
Response
8 fields
allowedOidcClientsarray of objects8 fields per item
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringusersarray of objects13 fields per item
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Get user group by ID
Section titled “Get user group by ID”/api/user-groups/{id}Retrieve detailed information about a specific user group including its users
Path parameters
idstringrequiredUser Group ID
Response
8 fields
allowedOidcClientsarray of objects8 fields per item
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringusersarray of objects13 fields per item
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Update user group
Section titled “Update user group”/api/user-groups/{id}Update an existing user group by ID
Path parameters
idstringrequiredUser Group ID
Body application/json
friendlyNamestringrequired2 to 50 characters
namestringrequired2 to 255 characters
Response
8 fields
allowedOidcClientsarray of objects8 fields per item
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringusersarray of objects13 fields per item
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Delete user group
Section titled “Delete user group”/api/user-groups/{id}Delete a specific user group by ID
Path parameters
idstringrequiredUser Group ID
Response
Update users in a group
Section titled “Update users in a group”/api/user-groups/{id}/usersUpdate the list of users belonging to a specific user group
Path parameters
idstringrequiredUser Group ID
Body application/json
userIdsarray of stringsrequired
Response
8 fields
allowedOidcClientsarray of objects8 fields per item
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringusersarray of objects13 fields per item
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
OIDC clients with their secrets, logos and allowed groups, plus the clients each user has authorized.
- get
/api/oidc/clientsList OIDC clients - post
/api/oidc/clientsCreate OIDC client - get
/api/oidc/clients/{id}Get OIDC client - put
/api/oidc/clients/{id}Update OIDC client - delete
/api/oidc/clients/{id}Delete OIDC client - put
/api/oidc/clients/{id}/allowed-user-groupsUpdate allowed user groups - get
/api/oidc/clients/{id}/logoGet client logo - post
/api/oidc/clients/{id}/logoUpdate client logo - delete
/api/oidc/clients/{id}/logoDelete client logo - get
/api/oidc/clients/{id}/metaGet client metadata - get
/api/oidc/clients/{id}/preview/{userId}Preview OIDC client data for user - post
/api/oidc/clients/{id}/refreshRefresh client metadata document - get
/api/oidc/clients/{id}/scim-service-providerGet SCIM service provider - get
/api/oidc/clients/{id}/secretsList client secrets - post
/api/oidc/clients/{id}/secretsCreate client secret - delete
/api/oidc/clients/{id}/secrets/{secretId}Delete client secret - post
/api/oidc/introspectIntrospect OIDC tokens - get
/api/oidc/logo-presetsSearch logo presets - get
/api/oidc/userinfoGet user information - get
/api/oidc/users/me/authorized-clientsList authorized clients for current user - delete
/api/oidc/users/me/authorized-clients/{clientId}Revoke authorization for an OIDC client - get
/api/oidc/users/me/clientsList accessible OIDC clients for current user - get
/api/oidc/users/{id}/authorized-clientsList authorized clients for a user - put
/api/user-groups/{id}/allowed-oidc-clientsUpdate allowed OIDC clients
List OIDC clients
Section titled “List OIDC clients”/api/oidc/clientsGet a paginated list of OIDC clients with optional search and sorting
Query parameters
searchstringSearch term to filter clients by name
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects21 fields per item
accessTokenDurationMinutesintegerallowedUserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
backchannelLogoutURLstringcallbackURLsarray of stringsclientTypestringcredentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
descriptionstringhasDarkLogobooleanhasLogobooleanidstringisGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoutCallbackURLsarray of stringsnamestringpkceEnabledbooleanpkceSupportedbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Create OIDC client
Section titled “Create OIDC client”/api/oidc/clientsCreate a new OIDC client
Body application/json
namestringrequiredat most 50 characters
accessTokenDurationMinutesintegerbackchannelLogoutURLstringcallbackURLsarray of stringscredentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
darkLogoUrlstringdescriptionstringat most 150 characters
hasDarkLogobooleanhasLogobooleanidstring2 to 128 characters
isGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoUrlstringlogoutCallbackURLsarray of stringspkceEnabledbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
Response
22 fields
accessTokenDurationMinutesintegerallowedUserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
backchannelLogoutURLstringcallbackURLsarray of stringsclientTypestringcreatedSecretobject6 fields
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
secretstring
credentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
descriptionstringhasDarkLogobooleanhasLogobooleanidstringisGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoutCallbackURLsarray of stringsnamestringpkceEnabledbooleanpkceSupportedbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
Get OIDC client
Section titled “Get OIDC client”/api/oidc/clients/{id}Get detailed information about an OIDC client
Path parameters
idstringrequiredClient ID
Response
21 fields
accessTokenDurationMinutesintegerallowedUserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
backchannelLogoutURLstringcallbackURLsarray of stringsclientTypestringcredentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
descriptionstringhasDarkLogobooleanhasLogobooleanidstringisGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoutCallbackURLsarray of stringsnamestringpkceEnabledbooleanpkceSupportedbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
Update OIDC client
Section titled “Update OIDC client”/api/oidc/clients/{id}Update an existing OIDC client
Path parameters
idstringrequiredClient ID
Body application/json
namestringrequiredat most 50 characters
accessTokenDurationMinutesintegerbackchannelLogoutURLstringcallbackURLsarray of stringscredentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
darkLogoUrlstringdescriptionstringat most 150 characters
hasDarkLogobooleanhasLogobooleanisGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoUrlstringlogoutCallbackURLsarray of stringspkceEnabledbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
Response
21 fields
accessTokenDurationMinutesintegerallowedUserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
backchannelLogoutURLstringcallbackURLsarray of stringsclientTypestringcredentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
descriptionstringhasDarkLogobooleanhasLogobooleanidstringisGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoutCallbackURLsarray of stringsnamestringpkceEnabledbooleanpkceSupportedbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
Delete OIDC client
Section titled “Delete OIDC client”/api/oidc/clients/{id}Delete an OIDC client by ID
Path parameters
idstringrequiredClient ID
Response
Update allowed user groups
Section titled “Update allowed user groups”/api/oidc/clients/{id}/allowed-user-groupsUpdate the user groups allowed to access an OIDC client
Path parameters
idstringrequiredClient ID
Body application/json
userGroupIdsarray of stringsrequired
Response
20 fields
accessTokenDurationMinutesintegerbackchannelLogoutURLstringcallbackURLsarray of stringsclientTypestringcredentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
descriptionstringhasDarkLogobooleanhasLogobooleanidstringisGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoutCallbackURLsarray of stringsnamestringpkceEnabledbooleanpkceSupportedbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
Get client logo
Section titled “Get client logo”/api/oidc/clients/{id}/logoGet the logo image for an OIDC client
Path parameters
idstringrequiredClient ID
Query parameters
lightbooleanLight mode logo (true) or dark mode logo (false)
Response
Update client logo
Section titled “Update client logo”/api/oidc/clients/{id}/logoUpload or update the logo for an OIDC client
Path parameters
idstringrequiredClient ID
Query parameters
lightbooleanLight mode logo (true) or dark mode logo (false)
Body multipart/form-data
filebinaryrequiredLogo image file (PNG, JPG, or SVG)
Response
Delete client logo
Section titled “Delete client logo”/api/oidc/clients/{id}/logoDelete the logo for an OIDC client
Path parameters
idstringrequiredClient ID
Query parameters
lightbooleanLight mode logo (true) or dark mode logo (false)
Response
Get client metadata
Section titled “Get client metadata”/api/oidc/clients/{id}/metaGet OIDC client metadata for discovery and configuration
Path parameters
idstringrequiredClient ID
Response
8 fields
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
Preview OIDC client data for user
Section titled “Preview OIDC client data for user”/api/oidc/clients/{id}/preview/{userId}Get a preview of the OIDC data (ID token, access token, userinfo) that would be sent to the client for a specific user
Path parameters
idstringrequiredClient ID
userIdstringrequiredUser ID to preview data for
Query parameters
scopesstringScopes to include in the preview (comma-separated)
Response
3 fields
accessTokenmap of valuesidTokenmap of valuesuserInfomap of values
Refresh client metadata document
Section titled “Refresh client metadata document”/api/oidc/clients/{id}/refreshForce a re-fetch of the OAuth Client ID Metadata Document for a CIMD client
Path parameters
idstringrequiredClient ID
Response
21 fields
accessTokenDurationMinutesintegerallowedUserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
backchannelLogoutURLstringcallbackURLsarray of stringsclientTypestringcredentialsobject2 fields
federatedIdentitiesarray of objects6 fields per item
audiencestringissuerstringjwksstringpublicKeysarray of objectsreplayProtectionbooleansubjectstring
secretsarray of objectsSecrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
descriptionstringhasDarkLogobooleanhasLogobooleanidstringisGroupRestrictedbooleanisPublicbooleanlaunchURLstringlogoutCallbackURLsarray of stringsnamestringpkceEnabledbooleanpkceSupportedbooleanrefreshTokenDurationMinutesintegerrequiresPushedAuthorizationRequestsbooleanrequiresReauthenticationbooleanskipConsentboolean
Get SCIM service provider
Section titled “Get SCIM service provider”/api/oidc/clients/{id}/scim-service-providerGet the SCIM service provider configuration for an OIDC client
Path parameters
idstringrequiredClient ID
Response
6 fields
createdAtstringendpointstringidstringlastSyncedAtstringoidcClientobject8 fields
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
tokenstring
List client secrets
Section titled “List client secrets”/api/oidc/clients/{id}/secretsList the secrets of an OIDC client, without disclosing their values
Path parameters
idstringrequiredClient ID
Response
5 fields per item
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
Create client secret
Section titled “Create client secret”/api/oidc/clients/{id}/secretsAdd a new secret to an OIDC client, leaving the existing ones usable. The value is only returned by this endpoint and cannot be retrieved later.
Path parameters
idstringrequiredClient ID
Body application/json
expiresAtstringExpiresAt makes the secret unusable after the given time (if nil, secrets don't expire)
secretstringSecret allows callers to supply their own value instead of having Pocket ID generate one
at least 16 characters
Response
6 fields
createdAtstringexpiresAtstringidstringisActivebooleanprefixstringPrefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column
secretstring
Delete client secret
Section titled “Delete client secret”/api/oidc/clients/{id}/secrets/{secretId}Delete a single secret of an OIDC client, making it immediately unusable
Path parameters
idstringrequiredClient ID
secretIdstringrequiredClient secret ID
Response
Introspect OIDC tokens
Section titled “Introspect OIDC tokens”/api/oidc/introspectPass a token to verify if it is considered valid.
Body multipart/form-data
tokenstringrequiredThe token to be introspected.
Response
Search logo presets
Section titled “Search logo presets”/api/oidc/logo-presetsSearch the selfh.st icon collection for logos that can be used for OIDC clients
Query parameters
searchstringSearch term matched against the icon name
Response
4 fields per item
darkLogoUrlstringlogoUrlstringnamestringreferencestring
Get user information
Section titled “Get user information”/api/oidc/userinfoGet user information based on the access token
Response
List authorized clients for current user
Section titled “List authorized clients for current user”/api/oidc/users/me/authorized-clientsGet a paginated list of OIDC clients that the current user has authorized
Query parameters
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
ascfilters[hasLaunchURL]booleanFilter clients by whether a launch URL is configured
Response
2 fields
dataarray of objects3 fields per item
clientobject8 fields
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
lastUsedAtstringscopestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Revoke authorization for an OIDC client
Section titled “Revoke authorization for an OIDC client”/api/oidc/users/me/authorized-clients/{clientId}Revoke the authorization for a specific OIDC client for the current user
Path parameters
clientIdstringrequiredClient ID to revoke authorization for
Response
List accessible OIDC clients for current user
Section titled “List accessible OIDC clients for current user”/api/oidc/users/me/clientsGet a list of OIDC clients that the current user can access
Query parameters
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
ascfilters[hasLaunchURL]booleanFilter clients by whether a launch URL is configured
Response
2 fields
dataarray of objects9 fields per item
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlastUsedAtstringlaunchURLstringnamestringrequiresReauthenticationboolean
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
List authorized clients for a user
Section titled “List authorized clients for a user”/api/oidc/users/{id}/authorized-clientsGet a paginated list of OIDC clients that a specific user has authorized
Path parameters
idstringrequiredUser ID
Query parameters
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
ascfilters[hasLaunchURL]booleanFilter clients by whether a launch URL is configured
Response
2 fields
dataarray of objects3 fields per item
clientobject8 fields
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
lastUsedAtstringscopestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Update allowed OIDC clients
Section titled “Update allowed OIDC clients”/api/user-groups/{id}/allowed-oidc-clientsUpdate the OIDC clients allowed for a specific user group
Path parameters
idstringrequiredUser Group ID
Body application/json
oidcClientIdsarray of stringsrequired
Response
8 fields
allowedOidcClientsarray of objects8 fields per item
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringusersarray of objects13 fields per item
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Your own APIs, their permissions and the clients that may request them.
- get
/api/api-access/{clientId}/apisList APIs a client may access - get
/api/api-access/{clientId}/assignable-apisList APIs a client can still be granted access to - get
/api/apisList APIs - post
/api/apisCreate API - get
/api/apis/{id}Get API by ID - put
/api/apis/{id}Update API - delete
/api/apis/{id}Delete API - get
/api/apis/{id}/assignable-clientsList clients that can still be granted access to an API - put
/api/apis/{id}/cimd-accessUpdate metadata document client access - get
/api/apis/{id}/clientsList clients with access to an API - put
/api/apis/{id}/clients/{clientId}Update a client's access to an API - delete
/api/apis/{id}/clients/{clientId}Revoke a client's access to an API - put
/api/apis/{id}/permissionsUpdate API permissions
List APIs a client may access
Section titled “List APIs a client may access”/api/api-access/{clientId}/apisGet every API the OIDC client may request tokens for, with its access and permissions split into user-delegated and client (machine-to-machine) access
Path parameters
clientIdstringrequiredOIDC Client ID
Response
7 fields per item
apiobject6 fields
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
cimdGrantedAccessbooleancimdGrantedPermissionIdsarray of stringsclientAccessbooleanclientPermissionIdsarray of stringsuserDelegatedAccessbooleanuserDelegatedPermissionIdsarray of strings
List APIs a client can still be granted access to
Section titled “List APIs a client can still be granted access to”/api/api-access/{clientId}/assignable-apisGet a paginated list of APIs the OIDC client cannot already reach
Path parameters
clientIdstringrequiredOIDC Client ID
Query parameters
searchstringSearch term to filter APIs by name or resource
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects6 fields per item
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
List APIs
Section titled “List APIs”/api/apisGet a paginated list of APIs with optional search and sorting
Query parameters
searchstringSearch term to filter APIs by name or resource
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects6 fields per item
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Create API
Section titled “Create API”/api/apisCreate a new API resource server
Body application/json
namestringrequired1 to 50 characters
resourcestringrequiredat most 350 characters
Response
6 fields
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
Get API by ID
Section titled “Get API by ID”/api/apis/{id}Retrieve a single API including its permissions
Path parameters
idstringrequiredAPI ID
Response
6 fields
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
Update API
Section titled “Update API”/api/apis/{id}Update an existing API by ID
Path parameters
idstringrequiredAPI ID
Body application/json
namestringrequired1 to 50 characters
Response
6 fields
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
Delete API
Section titled “Delete API”/api/apis/{id}Delete an API by ID
Path parameters
idstringrequiredAPI ID
Response
List clients that can still be granted access to an API
Section titled “List clients that can still be granted access to an API”/api/apis/{id}/assignable-clientsGet a paginated list of OIDC clients that have no grant on the API yet
Path parameters
idstringrequiredAPI ID
Query parameters
searchstringSearch term to filter clients by name
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects6 fields per item
clientTypestringhasDarkLogobooleanhasLogobooleanidstringisPublicbooleannamestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Update metadata document client access
Section titled “Update metadata document client access”/api/apis/{id}/cimd-accessReplace which permissions of an API every client registered through a Client ID Metadata Document may request
Path parameters
idstringrequiredAPI ID
Body application/json
permissionIdsarray of stringsrequiredenabledboolean
Response
6 fields
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
List clients with access to an API
Section titled “List clients with access to an API”/api/apis/{id}/clientsGet a paginated list of OIDC clients that may reach the API, with their permissions split into user-delegated and client (machine-to-machine) access
Path parameters
idstringrequiredAPI ID
Query parameters
searchstringSearch term to filter clients by name
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects7 fields per item
cimdGrantedAccessbooleancimdGrantedPermissionIdsarray of stringsclientobject6 fields
clientTypestringhasDarkLogobooleanhasLogobooleanidstringisPublicbooleannamestring
clientAccessbooleanclientPermissionIdsarray of stringsuserDelegatedAccessbooleanuserDelegatedPermissionIdsarray of strings
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Update a client's access to an API
Section titled “Update a client's access to an API”/api/apis/{id}/clients/{clientId}Replace the permissions of this API a single OIDC client may request, leaving its grants on other APIs untouched
Path parameters
idstringrequiredAPI ID
clientIdstringrequiredOIDC Client ID
Body application/json
clientPermissionIdsarray of stringsrequireduserDelegatedPermissionIdsarray of stringsrequiredclientAccessbooleanuserDelegatedAccessboolean
Response
4 fields
clientAccessbooleanclientPermissionIdsarray of stringsuserDelegatedAccessbooleanuserDelegatedPermissionIdsarray of strings
Revoke a client's access to an API
Section titled “Revoke a client's access to an API”/api/apis/{id}/clients/{clientId}Remove every permission of this API a single OIDC client was allowed to request
Path parameters
idstringrequiredAPI ID
clientIdstringrequiredOIDC Client ID
Response
Update API permissions
Section titled “Update API permissions”/api/apis/{id}/permissionsReplace the full set of permissions for an API
Path parameters
idstringrequiredAPI ID
Body application/json
permissionsarray of objects3 fields per item
keystringrequired1 to 128 characters
namestringrequired1 to 50 characters
descriptionstringat most 200 characters
Response
6 fields
allowCimdClientsbooleancreatedAtstringidstringnamestringpermissionsarray of objects5 fields per item
allowedForCimdClientsbooleandescriptionstringidstringkeystringnamestring
resourcestring
Custom Claims
Section titled “Custom Claims”Extra claims that Pocket ID adds to the tokens of a user or of every member of a group.
- get
/api/custom-claims/suggestionsGet custom claim suggestions - put
/api/custom-claims/user-group/{userGroupId}Update custom claims for a user group - put
/api/custom-claims/user/{userId}Update custom claims for a user
Get custom claim suggestions
Section titled “Get custom claim suggestions”/api/custom-claims/suggestionsGet a list of suggested custom claim names
Response
Update custom claims for a user group
Section titled “Update custom claims for a user group”/api/custom-claims/user-group/{userGroupId}Update or create custom claims for a specific user group
Path parameters
userGroupIdstringrequiredUser Group ID
Body application/json
An array, with these fields per item:
keystringrequiredvaluestringrequired
Response
2 fields per item
keystringvaluestring
Update custom claims for a user
Section titled “Update custom claims for a user”/api/custom-claims/user/{userId}Update or create custom claims for a specific user
Path parameters
userIdstringrequiredUser ID
Body application/json
An array, with these fields per item:
keystringrequiredvaluestringrequired
Response
2 fields per item
keystringvaluestring
API Keys
Section titled “API Keys”Keys for this REST API.
- get
/api/api-keysList API keys - post
/api/api-keysCreate API key - delete
/api/api-keys/{id}Revoke API key - post
/api/api-keys/{id}/renewRenew API key
List API keys
Section titled “List API keys”/api/api-keysGet a paginated list of API keys belonging to the current user
Query parameters
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects7 fields per item
createdAtstringdescriptionstringexpirationEmailSentbooleanexpiresAtstringidstringlastUsedAtstringnamestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
Create API key
Section titled “Create API key”/api/api-keysCreate a new API key for the current user
Body application/json
expiresAtstringrequirednamestringrequired3 to 50 characters
descriptionstring
Response
2 fields
apiKeyobject7 fields
createdAtstringdescriptionstringexpirationEmailSentbooleanexpiresAtstringidstringlastUsedAtstringnamestring
tokenstring
Revoke API key
Section titled “Revoke API key”/api/api-keys/{id}Revoke (delete) an existing API key by ID
Path parameters
idstringrequiredAPI Key ID
Response
Renew API key
Section titled “Renew API key”/api/api-keys/{id}/renewRenew an existing API key by ID
Path parameters
idstringrequiredAPI Key ID
Response
2 fields
apiKeyobject7 fields
createdAtstringdescriptionstringexpirationEmailSentbooleanexpiresAtstringidstringlastUsedAtstringnamestring
tokenstring
Application Configuration
Section titled “Application Configuration”The settings of the Application Configuration page, the LDAP sync and the test email.
- get
/api/application-configurationList public application configurations - put
/api/application-configurationUpdate application configurations - get
/api/application-configuration/allList all application configurations - post
/api/application-configuration/sync-ldapSynchronize LDAP - post
/api/application-configuration/test-emailSend test email
List public application configurations
Section titled “List public application configurations”/api/application-configurationGet all public application configurations
Response
3 fields per item
keystringtypestringvaluestring
Update application configurations
Section titled “Update application configurations”/api/application-configurationUpdate application configuration settings
Body application/json
allowOwnAccountEditstringrequiredallowUserSignupsstringrequiredOne of
disabled,withToken,openappNamestringrequired1 to 30 characters
autoCreateOidcClientSecretstringrequireddisableAnimationsstringrequiredemailApiKeyExpirationEnabledstringrequiredemailLoginNotificationEnabledstringrequiredemailOneTimeAccessAsAdminEnabledstringrequiredemailOneTimeAccessAsUnauthenticatedEnabledstringrequiredemailVerificationEnabledstringrequiredemailsVerifiedstringrequiredhomePageUrlstringrequiredldapEnabledstringrequiredldapSkipCertVerifystringrequiredldapSoftDeleteUsersstringrequiredoidcClientLogoPresetsEnabledstringrequiredrequireUserEmailstringrequiredsessionDurationstringrequiredsmtpSkipCertVerifystringrequiredsmtpTlsstringrequiredOne of
none,starttls,tlswebauthnAllowSyncedPasskeysstringrequiredwebauthnAuthenticatorAttachmentstringrequiredOne of
any,platform,cross-platformwebauthnUserVerificationstringrequiredOne of
required,preferredaccentColorstringcimdUrlAllowliststringldapAdminGroupNamestringldapAttributeGroupMemberstringldapAttributeGroupNamestringldapAttributeGroupUniqueIdentifierstringldapAttributeUserDisplayNamestringldapAttributeUserEmailstringldapAttributeUserFirstNamestringldapAttributeUserLastNamestringldapAttributeUserProfilePicturestringldapAttributeUserUniqueIdentifierstringldapAttributeUserUsernamestringldapBasestringldapBindDnstringldapBindPasswordstringldapUrlstringldapUserGroupSearchFilterstringldapUserSearchFilterstringsignupDefaultCustomClaimsstringsignupDefaultUserGroupIDsstringsmtpFromstringsmtpHoststringsmtpPasswordstringsmtpPortstringsmtpUserstring
Response
4 fields per item
isPublicbooleankeystringtypestringvaluestring
List all application configurations
Section titled “List all application configurations”/api/application-configuration/allGet all application configurations including private ones
Response
4 fields per item
isPublicbooleankeystringtypestringvaluestring
Synchronize LDAP
Section titled “Synchronize LDAP”/api/application-configuration/sync-ldapManually trigger LDAP synchronization
Response
Send test email
Section titled “Send test email”/api/application-configuration/test-emailSend a test email to verify email configuration
Response
Application Images
Section titled “Application Images”The logo, favicon, background, email logo and default profile picture.
- get
/api/application-images/backgroundGet background image - put
/api/application-images/backgroundUpdate background image - delete
/api/application-images/backgroundDelete background image - get
/api/application-images/default-profile-pictureGet default profile picture image - put
/api/application-images/default-profile-pictureUpdate default profile picture image - delete
/api/application-images/default-profile-pictureDelete default profile picture image - get
/api/application-images/emailGet email logo image - put
/api/application-images/emailUpdate email logo - get
/api/application-images/faviconGet favicon - put
/api/application-images/faviconUpdate favicon - get
/api/application-images/logoGet logo image - put
/api/application-images/logoUpdate logo - delete
/api/application-images/logoDelete logo image
Get background image
Section titled “Get background image”/api/application-images/backgroundGet the background image for the application
Response
Update background image
Section titled “Update background image”/api/application-images/backgroundUpdate the application background image
Body multipart/form-data
filebinaryrequiredBackground image file
Response
Delete background image
Section titled “Delete background image”/api/application-images/backgroundDelete the application background image
Response
Get default profile picture image
Section titled “Get default profile picture image”/api/application-images/default-profile-pictureGet the default profile picture image for the application
Response
Update default profile picture image
Section titled “Update default profile picture image”/api/application-images/default-profile-pictureUpdate the default profile picture image
Body multipart/form-data
filebinaryrequiredProfile picture image file
Response
Delete default profile picture image
Section titled “Delete default profile picture image”/api/application-images/default-profile-pictureDelete the default profile picture image
Response
Get email logo image
Section titled “Get email logo image”/api/application-images/emailGet the email logo image for use in emails
Response
Update email logo
Section titled “Update email logo”/api/application-images/emailUpdate the email logo for use in emails
Body multipart/form-data
filebinaryrequiredEmail logo image file
Response
Get favicon
Section titled “Get favicon”/api/application-images/faviconGet the favicon for the application
Response
Update favicon
Section titled “Update favicon”/api/application-images/faviconUpdate the application favicon
Body multipart/form-data
filebinaryrequiredFavicon file (.svg/.png/.ico)
Response
Get logo image
Section titled “Get logo image”/api/application-images/logoGet the logo image for the application
Query parameters
lightbooleanLight mode logo (true) or dark mode logo (false)
defaultbooleanReturn the bundled default logo if no custom logo is set (default true)
Response
Update logo
Section titled “Update logo”/api/application-images/logoUpdate the application logo
Query parameters
lightbooleanLight mode logo (true) or dark mode logo (false)
Body multipart/form-data
filebinaryrequiredLogo image file
Response
Delete logo image
Section titled “Delete logo image”/api/application-images/logoDelete the custom application logo and restore the default logo
Query parameters
lightbooleanLight mode logo (true) or dark mode logo (false)
Response
Audit Logs
Section titled “Audit Logs”Sign-ins and other security events, of the current user or of everyone.
- get
/api/audit-logsList audit logs - get
/api/audit-logs/allList all audit logs - get
/api/audit-logs/filters/client-namesList client names - get
/api/audit-logs/filters/usersList users with IDs
List audit logs
Section titled “List audit logs”/api/audit-logsGet a paginated list of audit logs for the current user
Query parameters
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects11 fields per item
actorUsernamestringcitystringcountrystringcreatedAtstringdatamap of stringsdevicestringeventstringidstringipAddressstringuserIDstringusernamestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
List all audit logs
Section titled “List all audit logs”/api/audit-logs/allGet a paginated list of all audit logs (admin only)
Query parameters
pagination[page]integerPage number for pagination
defaults to
1pagination[limit]integerNumber of items per page
defaults to
20sort[column]stringColumn to sort by
sort[direction]stringSort direction (asc or desc)
defaults to
asc
Response
2 fields
dataarray of objects11 fields per item
actorUsernamestringcitystringcountrystringcreatedAtstringdatamap of stringsdevicestringeventstringidstringipAddressstringuserIDstringusernamestring
paginationobject4 fields
currentPageintegeritemsPerPageintegertotalItemsintegertotalPagesinteger
List client names
Section titled “List client names”/api/audit-logs/filters/client-namesGet a list of all client names for audit log filtering
Response
List users with IDs
Section titled “List users with IDs”/api/audit-logs/filters/usersGet a list of all usernames with their IDs for audit log filtering
Response
SCIM provisioning of an OIDC client.
- post
/api/scim/service-providerCreate SCIM service provider - put
/api/scim/service-provider/{id}Update SCIM service provider - delete
/api/scim/service-provider/{id}Delete SCIM service provider - post
/api/scim/service-provider/{id}/syncSync SCIM service provider
Create SCIM service provider
Section titled “Create SCIM service provider”/api/scim/service-providerCreate a new SCIM service provider
Body application/json
endpointstringrequiredoidcClientIdstringrequiredtokenstring
Response
6 fields
createdAtstringendpointstringidstringlastSyncedAtstringoidcClientobject8 fields
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
tokenstring
Update SCIM service provider
Section titled “Update SCIM service provider”/api/scim/service-provider/{id}Update an existing SCIM service provider
Path parameters
idstringrequiredService Provider ID
Body application/json
endpointstringrequiredoidcClientIdstringrequiredtokenstring
Response
6 fields
createdAtstringendpointstringidstringlastSyncedAtstringoidcClientobject8 fields
clientTypestringdescriptionstringhasDarkLogobooleanhasLogobooleanidstringlaunchURLstringnamestringrequiresReauthenticationboolean
tokenstring
Delete SCIM service provider
Section titled “Delete SCIM service provider”/api/scim/service-provider/{id}Delete a SCIM service provider by ID
Path parameters
idstringrequiredService Provider ID
Response
Sync SCIM service provider
Section titled “Sync SCIM service provider”/api/scim/service-provider/{id}/syncTrigger synchronization for a SCIM service provider
Path parameters
idstringrequiredService Provider ID
Response
Device Login
Section titled “Device Login”The requests behind sign-in with another device.
- post
/api/device-login/requestsCreate device login request - post
/api/device-login/requests/{id}/exchangeExchange device login request - post
/api/device-login/verificationInspect device login request - post
/api/device-login/verification/decisionDecide device login request
Create device login request
Section titled “Create device login request”/api/device-login/requestsCreate a short-lived request that can be approved from another authenticated device
Response
6 fields
expiresAtstringidstringintervalintegeruserCodestringverificationUristringverificationUriCompletestring
Exchange device login request
Section titled “Exchange device login request”/api/device-login/requests/{id}/exchangeWait for a device login decision and create a browser session after it has been approved
Path parameters
idstringrequiredDevice login request ID
Responses
13 fields
customClaimsarray of objects2 fields per item
keystringvaluestring
disabledbooleandisplayNamestringemailstringemailVerifiedbooleanfirstNamestringidstringisAdminbooleanlastNamestringldapIdstringlocalestringuserGroupsarray of objects7 fields per item
createdAtstringcustomClaimsarray of objects2 fields per item
keystringvaluestring
friendlyNamestringidstringldapIdstringnamestringuserCountinteger
usernamestring
Inspect device login request
Section titled “Inspect device login request”/api/device-login/verificationRetrieve the requesting device details for an authenticated user before approval or denial
Body application/json
codestringrequired
Response
6 fields
citystringcountrystringdevicestringexpiresAtstringipAddressstringuserCodestring
Decide device login request
Section titled “Decide device login request”/api/device-login/verification/decisionApprove or deny a device login request; approval requires fresh passkey reauthentication
Body application/json
codestringrequireddecisionstringrequiredOne of
approve,deny
Response
Well Known
Section titled “Well Known”Discovery documents and signing keys, which OIDC clients read without authentication.
- get
/.well-known/jwks.jsonGet JSON Web Key Set (JWKS) - get
/.well-known/oauth-authorization-serverGet OAuth 2.0 authorization server metadata - get
/.well-known/openid-configurationGet OpenID Connect discovery configuration
Get JSON Web Key Set (JWKS)
Section titled “Get JSON Web Key Set (JWKS)”/.well-known/jwks.jsonReturns the JSON Web Key Set used for token verification
Response
Get OAuth 2.0 authorization server metadata
Section titled “Get OAuth 2.0 authorization server metadata”/.well-known/oauth-authorization-serverReturns the RFC 8414 OAuth 2.0 authorization server metadata document with endpoints and capabilities
Response
Get OpenID Connect discovery configuration
Section titled “Get OpenID Connect discovery configuration”/.well-known/openid-configurationReturns the OpenID Connect discovery document with endpoints and capabilities
Response
Version
Section titled “Version”The running version and the latest release.
- get
/api/version/currentGet current deployed version of Pocket ID - get
/api/version/latestGet latest available version of Pocket ID
Get current deployed version of Pocket ID
Section titled “Get current deployed version of Pocket ID”/api/version/currentResponse
Get latest available version of Pocket ID
Section titled “Get latest available version of Pocket ID”/api/version/latestResponse
Health
Section titled “Health”A health check for container orchestrators and load balancers.
Responds to healthchecks
Section titled “Responds to healthchecks”/healthzResponds with a successful status code to healthcheck requests
Response
Storage
Section titled “Storage”Storage warnings for the admin UI.
Get whether the SQLite storage warning should be shown
Section titled “Get whether the SQLite storage warning should be shown”/api/storage/sqlite-warningReports whether Pocket ID found its SQLite database on a networked filesystem, which is unsupported and can lead to database corruption
Response