authkit.app
AuthKit is WorkOS’s user authentication product for SaaS applications, providing hosted and embeddable sign-in flows with email/password, social login, MFA, magic auth, and enterprise SSO. The authkit.app domain is the AuthKit product site and tenant-hosted AuthKit domain pattern used within WorkOS.
authkit.app is AuthKit by WorkOS and exposes WorkOS’s authenticated developer surfaces: a REST API at `https://api.workos.com`, a Client GraphQL API token flow via the same API, and the `workos` npm CLI; no standalone authkit.app-native API surface was documented beyond AuthKit-hosted OAuth metadata for tenant subdomains.
- WorkOS Client GraphQL APIdiscovered
- WorkOS CLIdiscovered
In the WorkOS Dashboard API Keys page, create or copy an environment API key (sk_test_... or sk_live_...). For zero-account temporary environments, you can also provision one automatically by running `npx workos@latest install` or by calling `POST /x/one-shot-environments`; that returns an apiKey you can use immediately.
Mint this short-lived token from the WorkOS REST API by calling `POST /client/token` with your WorkOS API key and the target organization_id and user_id. The response returns token, which is the bearer token for the Client GraphQL API.
$ workos auth loginAcquired by the CLI — running workos auth login opens the auth flow and stores the credential.
conventions · 0/8 published
- integrations.json✗
/.well-known/integrations.json - llms.txt✗
/llms.txt - API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing