openapi: 3.2.0 info: title: Parlay Auth API description: Real-time sports odds aggregation from **33 books and data sources** updated every 2-120 seconds depending on source cadence. version: 3.2.0 x-credit-currency: credits x-credit-cost-catalogue-url: /v1/meta/credit-costs x-pricing-url: /v1/pricing x-usage-url: /v1/usage contact: name: ParlayAPI support url: https://parlay-api.com/support email: support@parlay-api.com license: name: ParlayAPI Terms of Service url: https://parlay-api.com/terms termsOfService: https://parlay-api.com/terms servers: - url: https://parlay-api.com description: Production (primary; HTTP/2, TLS 1.3). - url: https://api.parlay-api.com description: Production (high-volume; bypasses Cloudflare edge for trading bots above 30 req/min). Same origin, same auth, same endpoints. tags: - name: Auth paths: /signup: get: tags: - Auth summary: Signup Page operationId: signup_page_signup_get responses: '200': description: Successful Response content: text/html: schema: type: string post: tags: - Auth summary: Signup Submit operationId: signup_submit_signup_post requestBody: content: application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/Body_signup_submit_signup_post' required: true responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /login: get: tags: - Auth summary: Login Page operationId: login_page_login_get responses: '200': description: Successful Response content: text/html: schema: type: string post: tags: - Auth summary: Login Submit operationId: login_submit_login_post requestBody: content: application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/Body_login_submit_login_post' required: true responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /logout: get: tags: - Auth summary: Logout operationId: logout_logout_get responses: '200': description: Successful Response content: application/json: schema: {} /auth/magic: get: tags: - Auth summary: Magic Link Login description: 'Land here from a magic-link URL. Sets the session cookie from the sid query param and redirects to the dashboard. Used by the agent-signup flow: a session is created server-side at signup time and embedded in the URL; visiting the URL claims it.' operationId: magic_link_login_auth_magic_get responses: '200': description: Successful Response content: application/json: schema: {} /forgot-password: get: tags: - Auth summary: Forgot Password Page operationId: forgot_password_page_forgot_password_get responses: '200': description: Successful Response content: text/html: schema: type: string post: tags: - Auth summary: Forgot Password Submit description: 'Accept any email, generate a reset token, email the link. Always returns success to avoid enumerating which emails exist.' operationId: forgot_password_submit_forgot_password_post requestBody: content: application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/Body_forgot_password_submit_forgot_password_post' required: true responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /reset-password: get: tags: - Auth summary: Reset Password Page operationId: reset_password_page_reset_password_get parameters: - name: token in: query required: false schema: type: string default: '' title: Token responses: '200': description: Successful Response content: text/html: schema: type: string '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' post: tags: - Auth summary: Reset Password Submit operationId: reset_password_submit_reset_password_post requestBody: required: true content: application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/Body_reset_password_submit_reset_password_post' responses: '200': description: Successful Response content: application/json: schema: {} '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' components: schemas: Body_login_submit_login_post: properties: email: type: string title: Email password: type: string title: Password next: type: string title: Next default: /dashboard type: object required: - email - password title: Body_login_submit_login_post ValidationError: properties: loc: items: anyOf: - type: string - type: integer type: array title: Location msg: type: string title: Message type: type: string title: Error Type input: title: Input ctx: type: object title: Context type: object required: - loc - msg - type title: ValidationError Body_signup_submit_signup_post: properties: email: type: string title: Email password: type: string title: Password next: type: string title: Next default: '' attribution: type: string title: Attribution default: '' type: object required: - email - password title: Body_signup_submit_signup_post Body_forgot_password_submit_forgot_password_post: properties: email: type: string title: Email type: object required: - email title: Body_forgot_password_submit_forgot_password_post HTTPValidationError: properties: detail: items: $ref: '#/components/schemas/ValidationError' type: array title: Detail type: object title: HTTPValidationError Body_reset_password_submit_reset_password_post: properties: token: type: string title: Token password: type: string title: Password type: object required: - token - password title: Body_reset_password_submit_reset_password_post securitySchemes: apiKeyHeader: type: apiKey in: header name: X-API-Key description: API key passed in the X-API-Key header. Recommended. apiKeyQuery: type: apiKey in: query name: apiKey description: API key passed as the ?apiKey= query parameter. Useful for browser fetch() and webhooks where header control is limited. Equivalent to X-API-Key. bearerAuth: type: http scheme: bearer bearerFormat: APIKey description: 'API key passed via Authorization: Bearer . Equivalent to X-API-Key for compatibility with auth libraries that expect bearer tokens.'