Skip to content
v2.17.0GitHub

API endpoints

Every route of the Pocket ID REST API on one page, grouped by resource, with its parameters, request body and response fields.

Every route of the REST API, with the parameters it takes and the fields it answers with. The page comes from the backend's spec at every docs build, so it lists what the code serves.

Send an API key in the X-API-KEY header with each call. REST API covers creating keys and the shape of errors. The raw spec is available as swagger.json and swagger.yaml for Postman, code generators and AI assistants.

Users, their passkeys and profile pictures, login codes and signup tokens.

post/api/one-time-access-email

Request a one-time access email for unauthenticated users

Body application/json

  • emailstringrequired
  • redirectPathstring

Response

204 No Content
post/api/one-time-access-token/{token}

Exchange a one-time access token for a session token

Path parameters

  • tokenstringrequired

    One-time access token

Response

200 OKapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
post/api/signup

Create a new user account

Body application/json

  • usernamestringrequired

    1 to 50 characters

  • emailstring
  • firstNamestring

    at most 50 characters

  • lastNamestring

    at most 50 characters

  • tokenstring

Response

201 Createdapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
get/api/signup-tokens

Get a paginated list of signup tokens

Query parameters

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    7 fields per item
    • createdAtstring
    • expiresAtstring
    • idstring
    • tokenstring
    • usageCountinteger
    • usageLimitinteger
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
post/api/signup-tokens

Create a new signup token that allows user registration

Body application/json

  • ttlobjectrequired
  • usageLimitintegerrequired

    1 to 100

  • userGroupIdsarray of strings

Response

201 Createdapplication/json
7 fields
  • createdAtstring
  • expiresAtstring
  • idstring
  • tokenstring
  • usageCountinteger
  • usageLimitinteger
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
delete/api/signup-tokens/{id}

Delete a signup token by ID

Path parameters

  • idstringrequired

    Token ID

Response

204 No Content
post/api/signup/setup

Sign up and generate setup access token for initial admin user

Body application/json

  • usernamestringrequired

    1 to 50 characters

  • emailstring
  • firstNamestring

    at most 50 characters

  • lastNamestring

    at most 50 characters

  • tokenstring

Response

200 OKapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
get/api/users

Get a paginated list of users with optional search and sorting

Query parameters

  • searchstring

    Search term to filter users

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    13 fields per item
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • disabledboolean
    • displayNamestring
    • emailstring
    • emailVerifiedboolean
    • firstNamestring
    • idstring
    • isAdminboolean
    • lastNamestring
    • ldapIdstring
    • localestring
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • usernamestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
post/api/users

Create a new user

Body application/json

  • usernamestringrequired

    1 to 50 characters

  • disabledboolean
  • displayNamestring

    at most 100 characters

  • emailstring
  • emailVerifiedboolean
  • firstNamestring

    at most 50 characters

  • idstring
  • isAdminboolean
  • lastNamestring

    at most 50 characters

  • localestring
  • userGroupIdsarray of strings

Response

201 Createdapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
get/api/users/me

Retrieve information about the currently authenticated user

Response

200 OKapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
put/api/users/me

Update the currently authenticated user's information

Body application/json

  • usernamestringrequired

    1 to 50 characters

  • disabledboolean
  • displayNamestring

    at most 100 characters

  • emailstring
  • emailVerifiedboolean
  • firstNamestring

    at most 50 characters

  • idstring
  • isAdminboolean
  • lastNamestring

    at most 50 characters

  • localestring
  • userGroupIdsarray of strings

Response

200 OKapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
put/api/users/me/profile-picture

Update the currently authenticated user's profile picture

Body multipart/form-data

  • filebinaryrequired

    Profile picture image file (PNG, JPG, or JPEG)

Response

204 No Content
delete/api/users/me/profile-picture

Reset the currently authenticated user's profile picture to the default

Response

204 No Content
post/api/users/me/send-email-verification

Send an email verification to the currently authenticated user

Response

204 No Content
post/api/users/me/verify-email

Verify the currently authenticated user's email using a verification token

Body application/json

  • tokenstringrequired

Response

204 No Content
get/api/users/{id}

Retrieve detailed information about a specific user

Path parameters

  • idstringrequired

    User ID

Response

200 OKapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
put/api/users/{id}

Update an existing user by ID

Path parameters

  • idstringrequired

    User ID

Body application/json

  • usernamestringrequired

    1 to 50 characters

  • disabledboolean
  • displayNamestring

    at most 100 characters

  • emailstring
  • emailVerifiedboolean
  • firstNamestring

    at most 50 characters

  • idstring
  • isAdminboolean
  • lastNamestring

    at most 50 characters

  • localestring
  • userGroupIdsarray of strings

Response

200 OKapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
delete/api/users/{id}

Delete a specific user by ID

Path parameters

  • idstringrequired

    User ID

Response

204 No Content
get/api/users/{id}/groups

Retrieve all groups a specific user belongs to

Path parameters

  • idstringrequired

    User ID

Response

200 OKapplication/json
8 fields per item
  • allowedOidcClientsarray of objects
    8 fields per item
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • createdAtstring
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • friendlyNamestring
  • idstring
  • ldapIdstring
  • namestring
  • usersarray of objects
    13 fields per item
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • disabledboolean
    • displayNamestring
    • emailstring
    • emailVerifiedboolean
    • firstNamestring
    • idstring
    • isAdminboolean
    • lastNamestring
    • ldapIdstring
    • localestring
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • usernamestring
post/api/users/{id}/one-time-access-email

Request a one-time access email for a specific user (admin only)

Path parameters

  • idstringrequired

    User ID

Body application/json

  • ttlobject

Response

204 No Content

Create one-time access token for user (admin)

Section titled “Create one-time access token for user (admin)”
post/api/users/{id}/one-time-access-token

Generate a one-time access token for a specific user (admin only)

Path parameters

  • idstringrequired

    User ID

Body application/json

object

Response

201 application/json
put/api/users/{id}/profile-picture

Update a specific user's profile picture

Path parameters

  • idstringrequired

    User ID

Body multipart/form-data

  • filebinaryrequired

    Profile picture image file (PNG, JPG, or JPEG)

Response

204 No Content
delete/api/users/{id}/profile-picture

Reset a specific user's profile picture to the default

Path parameters

  • idstringrequired

    User ID

Response

204 No Content
get/api/users/{id}/profile-picture.png

Retrieve a specific user's profile picture

Path parameters

  • idstringrequired

    User ID

Response

200 image/png
put/api/users/{id}/user-groups

Update the groups a specific user belongs to

Path parameters

  • idstringrequired

    User ID

Body application/json

  • userGroupIdsarray of stringsrequired

Response

200 OKapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
get/api/users/{id}/webauthn-credentials

Retrieve all WebAuthn credentials for a specific user

Path parameters

  • idstringrequired

    User ID

Response

200 OKapplication/json
10 fields per item
  • aaguidstring
  • attestationTypestring
  • backupEligibleboolean
  • backupStateboolean
  • createdAtstring
  • credentialIDstring
  • hasIconboolean
  • idstring
  • namestring
  • transportarray of strings
delete/api/users/{id}/webauthn-credentials/{credentialId}

Delete a specific WebAuthn credential for a user

Path parameters

  • idstringrequired

    User ID

  • credentialIdstringrequired

    Credential ID

Response

204 No Content

Groups and their members.

get/api/user-groups

Get a paginated list of user groups with optional search and sorting

Query parameters

  • searchstring

    Search term to filter user groups by name

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
post/api/user-groups

Create a new user group

Body application/json

  • friendlyNamestringrequired

    2 to 50 characters

  • namestringrequired

    2 to 255 characters

Response

201 Created user groupapplication/json
8 fields
  • allowedOidcClientsarray of objects
    8 fields per item
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • createdAtstring
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • friendlyNamestring
  • idstring
  • ldapIdstring
  • namestring
  • usersarray of objects
    13 fields per item
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • disabledboolean
    • displayNamestring
    • emailstring
    • emailVerifiedboolean
    • firstNamestring
    • idstring
    • isAdminboolean
    • lastNamestring
    • ldapIdstring
    • localestring
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • usernamestring
get/api/user-groups/{id}

Retrieve detailed information about a specific user group including its users

Path parameters

  • idstringrequired

    User Group ID

Response

200 OKapplication/json
8 fields
  • allowedOidcClientsarray of objects
    8 fields per item
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • createdAtstring
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • friendlyNamestring
  • idstring
  • ldapIdstring
  • namestring
  • usersarray of objects
    13 fields per item
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • disabledboolean
    • displayNamestring
    • emailstring
    • emailVerifiedboolean
    • firstNamestring
    • idstring
    • isAdminboolean
    • lastNamestring
    • ldapIdstring
    • localestring
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • usernamestring
put/api/user-groups/{id}

Update an existing user group by ID

Path parameters

  • idstringrequired

    User Group ID

Body application/json

  • friendlyNamestringrequired

    2 to 50 characters

  • namestringrequired

    2 to 255 characters

Response

200 Updated user groupapplication/json
8 fields
  • allowedOidcClientsarray of objects
    8 fields per item
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • createdAtstring
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • friendlyNamestring
  • idstring
  • ldapIdstring
  • namestring
  • usersarray of objects
    13 fields per item
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • disabledboolean
    • displayNamestring
    • emailstring
    • emailVerifiedboolean
    • firstNamestring
    • idstring
    • isAdminboolean
    • lastNamestring
    • ldapIdstring
    • localestring
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • usernamestring
delete/api/user-groups/{id}

Delete a specific user group by ID

Path parameters

  • idstringrequired

    User Group ID

Response

204 No Content
put/api/user-groups/{id}/users

Update the list of users belonging to a specific user group

Path parameters

  • idstringrequired

    User Group ID

Body application/json

  • userIdsarray of stringsrequired

Response

200 OKapplication/json
8 fields
  • allowedOidcClientsarray of objects
    8 fields per item
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • createdAtstring
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • friendlyNamestring
  • idstring
  • ldapIdstring
  • namestring
  • usersarray of objects
    13 fields per item
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • disabledboolean
    • displayNamestring
    • emailstring
    • emailVerifiedboolean
    • firstNamestring
    • idstring
    • isAdminboolean
    • lastNamestring
    • ldapIdstring
    • localestring
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • usernamestring

OIDC clients with their secrets, logos and allowed groups, plus the clients each user has authorized.

get/api/oidc/clients

Get a paginated list of OIDC clients with optional search and sorting

Query parameters

  • searchstring

    Search term to filter clients by name

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    21 fields per item
    • accessTokenDurationMinutesinteger
    • allowedUserGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • backchannelLogoutURLstring
    • callbackURLsarray of strings
    • clientTypestring
    • credentialsobject
      2 fields
      • federatedIdentitiesarray of objects
        6 fields per item
        • audiencestring
        • issuerstring
        • jwksstring
        • publicKeysarray of objects
        • replayProtectionboolean
        • subjectstring
      • secretsarray of objects

        Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

        5 fields per item
        • createdAtstring
        • expiresAtstring
        • idstring
        • isActiveboolean
        • prefixstring

          Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • isGroupRestrictedboolean
    • isPublicboolean
    • launchURLstring
    • logoutCallbackURLsarray of strings
    • namestring
    • pkceEnabledboolean
    • pkceSupportedboolean
    • refreshTokenDurationMinutesinteger
    • requiresPushedAuthorizationRequestsboolean
    • requiresReauthenticationboolean
    • skipConsentboolean
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
post/api/oidc/clients

Create a new OIDC client

Body application/json

  • namestringrequired

    at most 50 characters

  • accessTokenDurationMinutesinteger
  • backchannelLogoutURLstring
  • callbackURLsarray of strings
  • credentialsobject
    2 fields
    • federatedIdentitiesarray of objects
      6 fields per item
      • audiencestring
      • issuerstring
      • jwksstring
      • publicKeysarray of objects
      • replayProtectionboolean
      • subjectstring
    • secretsarray of objects

      Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

      5 fields per item
      • createdAtstring
      • expiresAtstring
      • idstring
      • isActiveboolean
      • prefixstring

        Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • darkLogoUrlstring
  • descriptionstring

    at most 150 characters

  • hasDarkLogoboolean
  • hasLogoboolean
  • idstring

    2 to 128 characters

  • isGroupRestrictedboolean
  • isPublicboolean
  • launchURLstring
  • logoUrlstring
  • logoutCallbackURLsarray of strings
  • pkceEnabledboolean
  • refreshTokenDurationMinutesinteger
  • requiresPushedAuthorizationRequestsboolean
  • requiresReauthenticationboolean
  • skipConsentboolean

Response

201 Created clientapplication/json
22 fields
  • accessTokenDurationMinutesinteger
  • allowedUserGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • backchannelLogoutURLstring
  • callbackURLsarray of strings
  • clientTypestring
  • createdSecretobject
    6 fields
    • createdAtstring
    • expiresAtstring
    • idstring
    • isActiveboolean
    • prefixstring

      Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

    • secretstring
  • credentialsobject
    2 fields
    • federatedIdentitiesarray of objects
      6 fields per item
      • audiencestring
      • issuerstring
      • jwksstring
      • publicKeysarray of objects
      • replayProtectionboolean
      • subjectstring
    • secretsarray of objects

      Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

      5 fields per item
      • createdAtstring
      • expiresAtstring
      • idstring
      • isActiveboolean
      • prefixstring

        Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • descriptionstring
  • hasDarkLogoboolean
  • hasLogoboolean
  • idstring
  • isGroupRestrictedboolean
  • isPublicboolean
  • launchURLstring
  • logoutCallbackURLsarray of strings
  • namestring
  • pkceEnabledboolean
  • pkceSupportedboolean
  • refreshTokenDurationMinutesinteger
  • requiresPushedAuthorizationRequestsboolean
  • requiresReauthenticationboolean
  • skipConsentboolean
get/api/oidc/clients/{id}

Get detailed information about an OIDC client

Path parameters

  • idstringrequired

    Client ID

Response

200 Client informationapplication/json
21 fields
  • accessTokenDurationMinutesinteger
  • allowedUserGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • backchannelLogoutURLstring
  • callbackURLsarray of strings
  • clientTypestring
  • credentialsobject
    2 fields
    • federatedIdentitiesarray of objects
      6 fields per item
      • audiencestring
      • issuerstring
      • jwksstring
      • publicKeysarray of objects
      • replayProtectionboolean
      • subjectstring
    • secretsarray of objects

      Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

      5 fields per item
      • createdAtstring
      • expiresAtstring
      • idstring
      • isActiveboolean
      • prefixstring

        Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • descriptionstring
  • hasDarkLogoboolean
  • hasLogoboolean
  • idstring
  • isGroupRestrictedboolean
  • isPublicboolean
  • launchURLstring
  • logoutCallbackURLsarray of strings
  • namestring
  • pkceEnabledboolean
  • pkceSupportedboolean
  • refreshTokenDurationMinutesinteger
  • requiresPushedAuthorizationRequestsboolean
  • requiresReauthenticationboolean
  • skipConsentboolean
put/api/oidc/clients/{id}

Update an existing OIDC client

Path parameters

  • idstringrequired

    Client ID

Body application/json

  • namestringrequired

    at most 50 characters

  • accessTokenDurationMinutesinteger
  • backchannelLogoutURLstring
  • callbackURLsarray of strings
  • credentialsobject
    2 fields
    • federatedIdentitiesarray of objects
      6 fields per item
      • audiencestring
      • issuerstring
      • jwksstring
      • publicKeysarray of objects
      • replayProtectionboolean
      • subjectstring
    • secretsarray of objects

      Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

      5 fields per item
      • createdAtstring
      • expiresAtstring
      • idstring
      • isActiveboolean
      • prefixstring

        Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • darkLogoUrlstring
  • descriptionstring

    at most 150 characters

  • hasDarkLogoboolean
  • hasLogoboolean
  • isGroupRestrictedboolean
  • isPublicboolean
  • launchURLstring
  • logoUrlstring
  • logoutCallbackURLsarray of strings
  • pkceEnabledboolean
  • refreshTokenDurationMinutesinteger
  • requiresPushedAuthorizationRequestsboolean
  • requiresReauthenticationboolean
  • skipConsentboolean

Response

200 Updated clientapplication/json
21 fields
  • accessTokenDurationMinutesinteger
  • allowedUserGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • backchannelLogoutURLstring
  • callbackURLsarray of strings
  • clientTypestring
  • credentialsobject
    2 fields
    • federatedIdentitiesarray of objects
      6 fields per item
      • audiencestring
      • issuerstring
      • jwksstring
      • publicKeysarray of objects
      • replayProtectionboolean
      • subjectstring
    • secretsarray of objects

      Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

      5 fields per item
      • createdAtstring
      • expiresAtstring
      • idstring
      • isActiveboolean
      • prefixstring

        Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • descriptionstring
  • hasDarkLogoboolean
  • hasLogoboolean
  • idstring
  • isGroupRestrictedboolean
  • isPublicboolean
  • launchURLstring
  • logoutCallbackURLsarray of strings
  • namestring
  • pkceEnabledboolean
  • pkceSupportedboolean
  • refreshTokenDurationMinutesinteger
  • requiresPushedAuthorizationRequestsboolean
  • requiresReauthenticationboolean
  • skipConsentboolean
delete/api/oidc/clients/{id}

Delete an OIDC client by ID

Path parameters

  • idstringrequired

    Client ID

Response

204 No Content
put/api/oidc/clients/{id}/allowed-user-groups

Update the user groups allowed to access an OIDC client

Path parameters

  • idstringrequired

    Client ID

Body application/json

  • userGroupIdsarray of stringsrequired

Response

200 Updated clientapplication/json
20 fields
  • accessTokenDurationMinutesinteger
  • backchannelLogoutURLstring
  • callbackURLsarray of strings
  • clientTypestring
  • credentialsobject
    2 fields
    • federatedIdentitiesarray of objects
      6 fields per item
      • audiencestring
      • issuerstring
      • jwksstring
      • publicKeysarray of objects
      • replayProtectionboolean
      • subjectstring
    • secretsarray of objects

      Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

      5 fields per item
      • createdAtstring
      • expiresAtstring
      • idstring
      • isActiveboolean
      • prefixstring

        Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • descriptionstring
  • hasDarkLogoboolean
  • hasLogoboolean
  • idstring
  • isGroupRestrictedboolean
  • isPublicboolean
  • launchURLstring
  • logoutCallbackURLsarray of strings
  • namestring
  • pkceEnabledboolean
  • pkceSupportedboolean
  • refreshTokenDurationMinutesinteger
  • requiresPushedAuthorizationRequestsboolean
  • requiresReauthenticationboolean
  • skipConsentboolean
get/api/oidc/clients/{id}/logo

Get the logo image for an OIDC client

Path parameters

  • idstringrequired

    Client ID

Query parameters

  • lightboolean

    Light mode logo (true) or dark mode logo (false)

Response

200 image/png
post/api/oidc/clients/{id}/logo

Upload or update the logo for an OIDC client

Path parameters

  • idstringrequired

    Client ID

Query parameters

  • lightboolean

    Light mode logo (true) or dark mode logo (false)

Body multipart/form-data

  • filebinaryrequired

    Logo image file (PNG, JPG, or SVG)

Response

204 No Content
delete/api/oidc/clients/{id}/logo

Delete the logo for an OIDC client

Path parameters

  • idstringrequired

    Client ID

Query parameters

  • lightboolean

    Light mode logo (true) or dark mode logo (false)

Response

204 No Content
get/api/oidc/clients/{id}/meta

Get OIDC client metadata for discovery and configuration

Path parameters

  • idstringrequired

    Client ID

Response

200 Client metadataapplication/json
8 fields
  • clientTypestring
  • descriptionstring
  • hasDarkLogoboolean
  • hasLogoboolean
  • idstring
  • launchURLstring
  • namestring
  • requiresReauthenticationboolean
get/api/oidc/clients/{id}/preview/{userId}

Get a preview of the OIDC data (ID token, access token, userinfo) that would be sent to the client for a specific user

Path parameters

  • idstringrequired

    Client ID

  • userIdstringrequired

    User ID to preview data for

Query parameters

  • scopesstring

    Scopes to include in the preview (comma-separated)

Response

200 Preview data including ID token, access token, and userinfo payloadsapplication/json
3 fields
  • accessTokenmap of values
  • idTokenmap of values
  • userInfomap of values
post/api/oidc/clients/{id}/refresh

Force a re-fetch of the OAuth Client ID Metadata Document for a CIMD client

Path parameters

  • idstringrequired

    Client ID

Response

200 Refreshed clientapplication/json
21 fields
  • accessTokenDurationMinutesinteger
  • allowedUserGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • backchannelLogoutURLstring
  • callbackURLsarray of strings
  • clientTypestring
  • credentialsobject
    2 fields
    • federatedIdentitiesarray of objects
      6 fields per item
      • audiencestring
      • issuerstring
      • jwksstring
      • publicKeysarray of objects
      • replayProtectionboolean
      • subjectstring
    • secretsarray of objects

      Secrets is read-only: secrets are managed through the dedicated client secret endpoints and any value sent by a client is ignored

      5 fields per item
      • createdAtstring
      • expiresAtstring
      • idstring
      • isActiveboolean
      • prefixstring

        Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • descriptionstring
  • hasDarkLogoboolean
  • hasLogoboolean
  • idstring
  • isGroupRestrictedboolean
  • isPublicboolean
  • launchURLstring
  • logoutCallbackURLsarray of strings
  • namestring
  • pkceEnabledboolean
  • pkceSupportedboolean
  • refreshTokenDurationMinutesinteger
  • requiresPushedAuthorizationRequestsboolean
  • requiresReauthenticationboolean
  • skipConsentboolean
get/api/oidc/clients/{id}/scim-service-provider

Get the SCIM service provider configuration for an OIDC client

Path parameters

  • idstringrequired

    Client ID

Response

200 SCIM service provider configurationapplication/json
6 fields
  • createdAtstring
  • endpointstring
  • idstring
  • lastSyncedAtstring
  • oidcClientobject
    8 fields
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • tokenstring
get/api/oidc/clients/{id}/secrets

List the secrets of an OIDC client, without disclosing their values

Path parameters

  • idstringrequired

    Client ID

Response

200 Client secretsapplication/json
5 fields per item
  • createdAtstring
  • expiresAtstring
  • idstring
  • isActiveboolean
  • prefixstring

    Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

post/api/oidc/clients/{id}/secrets

Add a new secret to an OIDC client, leaving the existing ones usable. The value is only returned by this endpoint and cannot be retrieved later.

Path parameters

  • idstringrequired

    Client ID

Body application/json

  • expiresAtstring

    ExpiresAt makes the secret unusable after the given time (if nil, secrets don't expire)

  • secretstring

    Secret allows callers to supply their own value instead of having Pocket ID generate one

    at least 16 characters

Response

201 Created client secretapplication/json
6 fields
  • createdAtstring
  • expiresAtstring
  • idstring
  • isActiveboolean
  • prefixstring

    Prefix holds the first few characters of the secret in clear text, and is empty for secrets migrated from the single-secret column

  • secretstring
delete/api/oidc/clients/{id}/secrets/{secretId}

Delete a single secret of an OIDC client, making it immediately unusable

Path parameters

  • idstringrequired

    Client ID

  • secretIdstringrequired

    Client secret ID

Response

204 No content
post/api/oidc/introspect

Pass a token to verify if it is considered valid.

Body multipart/form-data

  • tokenstringrequired

    The token to be introspected.

Response

200 application/json
get/api/oidc/logo-presets

Search the selfh.st icon collection for logos that can be used for OIDC clients

Query parameters

  • searchstring

    Search term matched against the icon name

Response

200 OKapplication/json
4 fields per item
  • darkLogoUrlstring
  • logoUrlstring
  • namestring
  • referencestring
get/api/oidc/userinfo

Get user information based on the access token

Response

200 application/json
get/api/oidc/users/me/authorized-clients

Get a paginated list of OIDC clients that the current user has authorized

Query parameters

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

  • filters[hasLaunchURL]boolean

    Filter clients by whether a launch URL is configured

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    3 fields per item
    • clientobject
      8 fields
      • clientTypestring
      • descriptionstring
      • hasDarkLogoboolean
      • hasLogoboolean
      • idstring
      • launchURLstring
      • namestring
      • requiresReauthenticationboolean
    • lastUsedAtstring
    • scopestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
delete/api/oidc/users/me/authorized-clients/{clientId}

Revoke the authorization for a specific OIDC client for the current user

Path parameters

  • clientIdstringrequired

    Client ID to revoke authorization for

Response

204 No Content

List accessible OIDC clients for current user

Section titled “List accessible OIDC clients for current user”
get/api/oidc/users/me/clients

Get a list of OIDC clients that the current user can access

Query parameters

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

  • filters[hasLaunchURL]boolean

    Filter clients by whether a launch URL is configured

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    9 fields per item
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • lastUsedAtstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
get/api/oidc/users/{id}/authorized-clients

Get a paginated list of OIDC clients that a specific user has authorized

Path parameters

  • idstringrequired

    User ID

Query parameters

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

  • filters[hasLaunchURL]boolean

    Filter clients by whether a launch URL is configured

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    3 fields per item
    • clientobject
      8 fields
      • clientTypestring
      • descriptionstring
      • hasDarkLogoboolean
      • hasLogoboolean
      • idstring
      • launchURLstring
      • namestring
      • requiresReauthenticationboolean
    • lastUsedAtstring
    • scopestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
put/api/user-groups/{id}/allowed-oidc-clients

Update the OIDC clients allowed for a specific user group

Path parameters

  • idstringrequired

    User Group ID

Body application/json

  • oidcClientIdsarray of stringsrequired

Response

200 Updated user groupapplication/json
8 fields
  • allowedOidcClientsarray of objects
    8 fields per item
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • createdAtstring
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • friendlyNamestring
  • idstring
  • ldapIdstring
  • namestring
  • usersarray of objects
    13 fields per item
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • disabledboolean
    • displayNamestring
    • emailstring
    • emailVerifiedboolean
    • firstNamestring
    • idstring
    • isAdminboolean
    • lastNamestring
    • ldapIdstring
    • localestring
    • userGroupsarray of objects
      7 fields per item
      • createdAtstring
      • customClaimsarray of objects
        2 fields per item
        • keystring
        • valuestring
      • friendlyNamestring
      • idstring
      • ldapIdstring
      • namestring
      • userCountinteger
    • usernamestring

Your own APIs, their permissions and the clients that may request them.

get/api/api-access/{clientId}/apis

Get every API the OIDC client may request tokens for, with its access and permissions split into user-delegated and client (machine-to-machine) access

Path parameters

  • clientIdstringrequired

    OIDC Client ID

Response

200 OKapplication/json
7 fields per item
  • apiobject
    6 fields
    • allowCimdClientsboolean
    • createdAtstring
    • idstring
    • namestring
    • permissionsarray of objects
      5 fields per item
      • allowedForCimdClientsboolean
      • descriptionstring
      • idstring
      • keystring
      • namestring
    • resourcestring
  • cimdGrantedAccessboolean
  • cimdGrantedPermissionIdsarray of strings
  • clientAccessboolean
  • clientPermissionIdsarray of strings
  • userDelegatedAccessboolean
  • userDelegatedPermissionIdsarray of strings

List APIs a client can still be granted access to

Section titled “List APIs a client can still be granted access to”
get/api/api-access/{clientId}/assignable-apis

Get a paginated list of APIs the OIDC client cannot already reach

Path parameters

  • clientIdstringrequired

    OIDC Client ID

Query parameters

  • searchstring

    Search term to filter APIs by name or resource

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    6 fields per item
    • allowCimdClientsboolean
    • createdAtstring
    • idstring
    • namestring
    • permissionsarray of objects
      5 fields per item
      • allowedForCimdClientsboolean
      • descriptionstring
      • idstring
      • keystring
      • namestring
    • resourcestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
get/api/apis

Get a paginated list of APIs with optional search and sorting

Query parameters

  • searchstring

    Search term to filter APIs by name or resource

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    6 fields per item
    • allowCimdClientsboolean
    • createdAtstring
    • idstring
    • namestring
    • permissionsarray of objects
      5 fields per item
      • allowedForCimdClientsboolean
      • descriptionstring
      • idstring
      • keystring
      • namestring
    • resourcestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
post/api/apis

Create a new API resource server

Body application/json

  • namestringrequired

    1 to 50 characters

  • resourcestringrequired

    at most 350 characters

Response

201 Created APIapplication/json
6 fields
  • allowCimdClientsboolean
  • createdAtstring
  • idstring
  • namestring
  • permissionsarray of objects
    5 fields per item
    • allowedForCimdClientsboolean
    • descriptionstring
    • idstring
    • keystring
    • namestring
  • resourcestring
get/api/apis/{id}

Retrieve a single API including its permissions

Path parameters

  • idstringrequired

    API ID

Response

200 OKapplication/json
6 fields
  • allowCimdClientsboolean
  • createdAtstring
  • idstring
  • namestring
  • permissionsarray of objects
    5 fields per item
    • allowedForCimdClientsboolean
    • descriptionstring
    • idstring
    • keystring
    • namestring
  • resourcestring
put/api/apis/{id}

Update an existing API by ID

Path parameters

  • idstringrequired

    API ID

Body application/json

  • namestringrequired

    1 to 50 characters

Response

200 Updated APIapplication/json
6 fields
  • allowCimdClientsboolean
  • createdAtstring
  • idstring
  • namestring
  • permissionsarray of objects
    5 fields per item
    • allowedForCimdClientsboolean
    • descriptionstring
    • idstring
    • keystring
    • namestring
  • resourcestring
delete/api/apis/{id}

Delete an API by ID

Path parameters

  • idstringrequired

    API ID

Response

204 No Content

List clients that can still be granted access to an API

Section titled “List clients that can still be granted access to an API”
get/api/apis/{id}/assignable-clients

Get a paginated list of OIDC clients that have no grant on the API yet

Path parameters

  • idstringrequired

    API ID

Query parameters

  • searchstring

    Search term to filter clients by name

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    6 fields per item
    • clientTypestring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • isPublicboolean
    • namestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
put/api/apis/{id}/cimd-access

Replace which permissions of an API every client registered through a Client ID Metadata Document may request

Path parameters

  • idstringrequired

    API ID

Body application/json

  • permissionIdsarray of stringsrequired
  • enabledboolean

Response

200 Updated APIapplication/json
6 fields
  • allowCimdClientsboolean
  • createdAtstring
  • idstring
  • namestring
  • permissionsarray of objects
    5 fields per item
    • allowedForCimdClientsboolean
    • descriptionstring
    • idstring
    • keystring
    • namestring
  • resourcestring
get/api/apis/{id}/clients

Get a paginated list of OIDC clients that may reach the API, with their permissions split into user-delegated and client (machine-to-machine) access

Path parameters

  • idstringrequired

    API ID

Query parameters

  • searchstring

    Search term to filter clients by name

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    7 fields per item
    • cimdGrantedAccessboolean
    • cimdGrantedPermissionIdsarray of strings
    • clientobject
      6 fields
      • clientTypestring
      • hasDarkLogoboolean
      • hasLogoboolean
      • idstring
      • isPublicboolean
      • namestring
    • clientAccessboolean
    • clientPermissionIdsarray of strings
    • userDelegatedAccessboolean
    • userDelegatedPermissionIdsarray of strings
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
put/api/apis/{id}/clients/{clientId}

Replace the permissions of this API a single OIDC client may request, leaving its grants on other APIs untouched

Path parameters

  • idstringrequired

    API ID

  • clientIdstringrequired

    OIDC Client ID

Body application/json

  • clientPermissionIdsarray of stringsrequired
  • userDelegatedPermissionIdsarray of stringsrequired
  • clientAccessboolean
  • userDelegatedAccessboolean

Response

200 OKapplication/json
4 fields
  • clientAccessboolean
  • clientPermissionIdsarray of strings
  • userDelegatedAccessboolean
  • userDelegatedPermissionIdsarray of strings
delete/api/apis/{id}/clients/{clientId}

Remove every permission of this API a single OIDC client was allowed to request

Path parameters

  • idstringrequired

    API ID

  • clientIdstringrequired

    OIDC Client ID

Response

204 No Content
put/api/apis/{id}/permissions

Replace the full set of permissions for an API

Path parameters

  • idstringrequired

    API ID

Body application/json

  • permissionsarray of objects
    3 fields per item
    • keystringrequired

      1 to 128 characters

    • namestringrequired

      1 to 50 characters

    • descriptionstring

      at most 200 characters

Response

200 Updated APIapplication/json
6 fields
  • allowCimdClientsboolean
  • createdAtstring
  • idstring
  • namestring
  • permissionsarray of objects
    5 fields per item
    • allowedForCimdClientsboolean
    • descriptionstring
    • idstring
    • keystring
    • namestring
  • resourcestring

Extra claims that Pocket ID adds to the tokens of a user or of every member of a group.

get/api/custom-claims/suggestions

Get a list of suggested custom claim names

Response

200 application/json
put/api/custom-claims/user-group/{userGroupId}

Update or create custom claims for a specific user group

Path parameters

  • userGroupIdstringrequired

    User Group ID

Body application/json

An array, with these fields per item:

  • keystringrequired
  • valuestringrequired

Response

200 Updated custom claimsapplication/json
2 fields per item
  • keystring
  • valuestring
put/api/custom-claims/user/{userId}

Update or create custom claims for a specific user

Path parameters

  • userIdstringrequired

    User ID

Body application/json

An array, with these fields per item:

  • keystringrequired
  • valuestringrequired

Response

200 Updated custom claimsapplication/json
2 fields per item
  • keystring
  • valuestring

Keys for this REST API.

get/api/api-keys

Get a paginated list of API keys belonging to the current user

Query parameters

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    7 fields per item
    • createdAtstring
    • descriptionstring
    • expirationEmailSentboolean
    • expiresAtstring
    • idstring
    • lastUsedAtstring
    • namestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
post/api/api-keys

Create a new API key for the current user

Body application/json

  • expiresAtstringrequired
  • namestringrequired

    3 to 50 characters

  • descriptionstring

Response

201 Created API key with tokenapplication/json
2 fields
  • apiKeyobject
    7 fields
    • createdAtstring
    • descriptionstring
    • expirationEmailSentboolean
    • expiresAtstring
    • idstring
    • lastUsedAtstring
    • namestring
  • tokenstring
delete/api/api-keys/{id}

Revoke (delete) an existing API key by ID

Path parameters

  • idstringrequired

    API Key ID

Response

204 No Content
post/api/api-keys/{id}/renew

Renew an existing API key by ID

Path parameters

  • idstringrequired

    API Key ID

Response

200 Renewed API key with new tokenapplication/json
2 fields
  • apiKeyobject
    7 fields
    • createdAtstring
    • descriptionstring
    • expirationEmailSentboolean
    • expiresAtstring
    • idstring
    • lastUsedAtstring
    • namestring
  • tokenstring

The settings of the Application Configuration page, the LDAP sync and the test email.

get/api/application-configuration

Get all public application configurations

Response

200 OKapplication/json
3 fields per item
  • keystring
  • typestring
  • valuestring
put/api/application-configuration

Update application configuration settings

Body application/json

  • allowOwnAccountEditstringrequired
  • allowUserSignupsstringrequired

    One of disabled, withToken, open

  • appNamestringrequired

    1 to 30 characters

  • autoCreateOidcClientSecretstringrequired
  • disableAnimationsstringrequired
  • emailApiKeyExpirationEnabledstringrequired
  • emailLoginNotificationEnabledstringrequired
  • emailOneTimeAccessAsAdminEnabledstringrequired
  • emailOneTimeAccessAsUnauthenticatedEnabledstringrequired
  • emailVerificationEnabledstringrequired
  • emailsVerifiedstringrequired
  • homePageUrlstringrequired
  • ldapEnabledstringrequired
  • ldapSkipCertVerifystringrequired
  • ldapSoftDeleteUsersstringrequired
  • oidcClientLogoPresetsEnabledstringrequired
  • requireUserEmailstringrequired
  • sessionDurationstringrequired
  • smtpSkipCertVerifystringrequired
  • smtpTlsstringrequired

    One of none, starttls, tls

  • webauthnAllowSyncedPasskeysstringrequired
  • webauthnAuthenticatorAttachmentstringrequired

    One of any, platform, cross-platform

  • webauthnUserVerificationstringrequired

    One of required, preferred

  • accentColorstring
  • cimdUrlAllowliststring
  • ldapAdminGroupNamestring
  • ldapAttributeGroupMemberstring
  • ldapAttributeGroupNamestring
  • ldapAttributeGroupUniqueIdentifierstring
  • ldapAttributeUserDisplayNamestring
  • ldapAttributeUserEmailstring
  • ldapAttributeUserFirstNamestring
  • ldapAttributeUserLastNamestring
  • ldapAttributeUserProfilePicturestring
  • ldapAttributeUserUniqueIdentifierstring
  • ldapAttributeUserUsernamestring
  • ldapBasestring
  • ldapBindDnstring
  • ldapBindPasswordstring
  • ldapUrlstring
  • ldapUserGroupSearchFilterstring
  • ldapUserSearchFilterstring
  • signupDefaultCustomClaimsstring
  • signupDefaultUserGroupIDsstring
  • smtpFromstring
  • smtpHoststring
  • smtpPasswordstring
  • smtpPortstring
  • smtpUserstring

Response

200 OKapplication/json
4 fields per item
  • isPublicboolean
  • keystring
  • typestring
  • valuestring
get/api/application-configuration/all

Get all application configurations including private ones

Response

200 OKapplication/json
4 fields per item
  • isPublicboolean
  • keystring
  • typestring
  • valuestring
post/api/application-configuration/sync-ldap

Manually trigger LDAP synchronization

Response

204 No Content
post/api/application-configuration/test-email

Send a test email to verify email configuration

Response

204 No Content

The logo, favicon, background, email logo and default profile picture.

get/api/application-images/background

Get the background image for the application

Response

200 image/png
put/api/application-images/background

Update the application background image

Body multipart/form-data

  • filebinaryrequired

    Background image file

Response

204 No Content
delete/api/application-images/background

Delete the application background image

Response

204 No Content
get/api/application-images/default-profile-picture

Get the default profile picture image for the application

Response

200 image/png
put/api/application-images/default-profile-picture

Update the default profile picture image

Body multipart/form-data

  • filebinaryrequired

    Profile picture image file

Response

204 No Content
delete/api/application-images/default-profile-picture

Delete the default profile picture image

Response

204 No Content
get/api/application-images/email

Get the email logo image for use in emails

Response

200 image/png
put/api/application-images/email

Update the email logo for use in emails

Body multipart/form-data

  • filebinaryrequired

    Email logo image file

Response

204 No Content
get/api/application-images/favicon

Get the favicon for the application

Response

200 image/x-icon
put/api/application-images/favicon

Update the application favicon

Body multipart/form-data

  • filebinaryrequired

    Favicon file (.svg/.png/.ico)

Response

204 No Content
get/api/application-images/logo

Get the logo image for the application

Query parameters

  • lightboolean

    Light mode logo (true) or dark mode logo (false)

  • defaultboolean

    Return the bundled default logo if no custom logo is set (default true)

Response

200 image/png
put/api/application-images/logo

Update the application logo

Query parameters

  • lightboolean

    Light mode logo (true) or dark mode logo (false)

Body multipart/form-data

  • filebinaryrequired

    Logo image file

Response

204 No Content
delete/api/application-images/logo

Delete the custom application logo and restore the default logo

Query parameters

  • lightboolean

    Light mode logo (true) or dark mode logo (false)

Response

204 No Content

Sign-ins and other security events, of the current user or of everyone.

get/api/audit-logs

Get a paginated list of audit logs for the current user

Query parameters

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    11 fields per item
    • actorUsernamestring
    • citystring
    • countrystring
    • createdAtstring
    • datamap of strings
    • devicestring
    • eventstring
    • idstring
    • ipAddressstring
    • userIDstring
    • usernamestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
get/api/audit-logs/all

Get a paginated list of all audit logs (admin only)

Query parameters

  • pagination[page]integer

    Page number for pagination

    defaults to 1

  • pagination[limit]integer

    Number of items per page

    defaults to 20

  • sort[column]string

    Column to sort by

  • sort[direction]string

    Sort direction (asc or desc)

    defaults to asc

Response

200 OKapplication/json
2 fields
  • dataarray of objects
    11 fields per item
    • actorUsernamestring
    • citystring
    • countrystring
    • createdAtstring
    • datamap of strings
    • devicestring
    • eventstring
    • idstring
    • ipAddressstring
    • userIDstring
    • usernamestring
  • paginationobject
    4 fields
    • currentPageinteger
    • itemsPerPageinteger
    • totalItemsinteger
    • totalPagesinteger
get/api/audit-logs/filters/client-names

Get a list of all client names for audit log filtering

Response

200 application/json
get/api/audit-logs/filters/users

Get a list of all usernames with their IDs for audit log filtering

Response

200 application/json

SCIM provisioning of an OIDC client.

post/api/scim/service-provider

Create a new SCIM service provider

Body application/json

  • endpointstringrequired
  • oidcClientIdstringrequired
  • tokenstring

Response

201 Created SCIM service providerapplication/json
6 fields
  • createdAtstring
  • endpointstring
  • idstring
  • lastSyncedAtstring
  • oidcClientobject
    8 fields
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • tokenstring
put/api/scim/service-provider/{id}

Update an existing SCIM service provider

Path parameters

  • idstringrequired

    Service Provider ID

Body application/json

  • endpointstringrequired
  • oidcClientIdstringrequired
  • tokenstring

Response

200 Updated SCIM service providerapplication/json
6 fields
  • createdAtstring
  • endpointstring
  • idstring
  • lastSyncedAtstring
  • oidcClientobject
    8 fields
    • clientTypestring
    • descriptionstring
    • hasDarkLogoboolean
    • hasLogoboolean
    • idstring
    • launchURLstring
    • namestring
    • requiresReauthenticationboolean
  • tokenstring
delete/api/scim/service-provider/{id}

Delete a SCIM service provider by ID

Path parameters

  • idstringrequired

    Service Provider ID

Response

204 No Content
post/api/scim/service-provider/{id}/sync

Trigger synchronization for a SCIM service provider

Path parameters

  • idstringrequired

    Service Provider ID

Response

200 OK

The requests behind sign-in with another device.

post/api/device-login/requests

Create a short-lived request that can be approved from another authenticated device

Response

201 Created device login requestapplication/json
6 fields
  • expiresAtstring
  • idstring
  • intervalinteger
  • userCodestring
  • verificationUristring
  • verificationUriCompletestring
post/api/device-login/requests/{id}/exchange

Wait for a device login decision and create a browser session after it has been approved

Path parameters

  • idstringrequired

    Device login request ID

Responses

200 Approved request exchanged for a user sessionapplication/json
13 fields
  • customClaimsarray of objects
    2 fields per item
    • keystring
    • valuestring
  • disabledboolean
  • displayNamestring
  • emailstring
  • emailVerifiedboolean
  • firstNamestring
  • idstring
  • isAdminboolean
  • lastNamestring
  • ldapIdstring
  • localestring
  • userGroupsarray of objects
    7 fields per item
    • createdAtstring
    • customClaimsarray of objects
      2 fields per item
      • keystring
      • valuestring
    • friendlyNamestring
    • idstring
    • ldapIdstring
    • namestring
    • userCountinteger
  • usernamestring
202 Authorization pending
post/api/device-login/verification

Retrieve the requesting device details for an authenticated user before approval or denial

Body application/json

  • codestringrequired

Response

200 Device login request detailsapplication/json
6 fields
  • citystring
  • countrystring
  • devicestring
  • expiresAtstring
  • ipAddressstring
  • userCodestring
post/api/device-login/verification/decision

Approve or deny a device login request; approval requires fresh passkey reauthentication

Body application/json

  • codestringrequired
  • decisionstringrequired

    One of approve, deny

Response

204 No Content

Discovery documents and signing keys, which OIDC clients read without authentication.

get/.well-known/jwks.json

Returns the JSON Web Key Set used for token verification

Response

200 application/json

Get OAuth 2.0 authorization server metadata

Section titled “Get OAuth 2.0 authorization server metadata”
get/.well-known/oauth-authorization-server

Returns the RFC 8414 OAuth 2.0 authorization server metadata document with endpoints and capabilities

Response

200 application/json

Get OpenID Connect discovery configuration

Section titled “Get OpenID Connect discovery configuration”
get/.well-known/openid-configuration

Returns the OpenID Connect discovery document with endpoints and capabilities

Response

200 application/json

The running version and the latest release.

get/api/version/current

Response

200 application/json
get/api/version/latest

Response

200 application/json

A health check for container orchestrators and load balancers.

get/healthz

Responds with a successful status code to healthcheck requests

Response

204

Storage warnings for the admin UI.

Get whether the SQLite storage warning should be shown

Section titled “Get whether the SQLite storage warning should be shown”
get/api/storage/sqlite-warning

Reports whether Pocket ID found its SQLite database on a networked filesystem, which is unsupported and can lead to database corruption

Response

200 application/json