openapi: 3.1.0 info: title: Authsignal Server Actions Authenticators API description: 'Best-effort OpenAPI 3.1 description of the Authsignal Server API (v1). Authsignal provides drop-in MFA, passwordless and risk-based authentication. Derived from public docs at https://docs.authsignal.com/api-reference/server-api/overview and the OpenAPI spec referenced at https://docs.authsignal.com/server-api.json. ' version: '1' contact: name: Authsignal Docs url: https://docs.authsignal.com/api-reference/server-api/overview servers: - url: https://api.authsignal.com/v1 description: US (Oregon) - url: https://eu.api.authsignal.com/v1 description: EU (Ireland) - url: https://au.api.authsignal.com/v1 description: AU (Sydney) - url: https://ca.api.authsignal.com/v1 description: CA (Montreal) security: - basicAuth: [] tags: - name: Authenticators paths: /authenticators: get: tags: - Authenticators summary: Get tenant authenticators operationId: getAuthenticators responses: '200': description: Authenticators returned /users/{userId}/authenticators: parameters: - $ref: '#/components/parameters/UserId' get: tags: - Authenticators summary: Get user authenticators operationId: getUserAuthenticators responses: '200': description: User authenticators returned post: tags: - Authenticators summary: Enroll authenticator operationId: enrollAuthenticator responses: '201': description: Authenticator enrolled /users/{userId}/authenticators/{userAuthenticatorId}: parameters: - $ref: '#/components/parameters/UserId' - in: path name: userAuthenticatorId required: true schema: type: string delete: tags: - Authenticators summary: Delete authenticator operationId: deleteAuthenticator responses: '204': description: Deleted /users/authenticators: post: tags: - Authenticators summary: Batch enroll passkeys operationId: batchEnrollAuthenticators responses: '200': description: Authenticators enrolled components: parameters: UserId: in: path name: userId required: true schema: type: string description: Authsignal user ID securitySchemes: basicAuth: type: http scheme: basic description: 'HTTP Basic auth where the username is the Authsignal tenant secret API key and the password is empty. '