goauthentik.io
authentik is an identity and access management platform for self-hosted or managed deployments. It provides authentication, authorization, and application integration features including OAuth2/OIDC and related identity-provider capabilities.
authentik exposes a tenant-hosted REST API with an OpenAPI schema; it documents bearer-token auth via user-created API tokens or OAuth access tokens with the `goauthentik.io/api` scope. It also documents WebSocket endpoints, but these are not recorded as separate supported surface types here.
- authentik REST APIdiscovered
In your own authentik instance, sign in and create a user token as described in the API authentication docs. The API docs state users can create tokens to authenticate as any user with a static key. Instance-specific admin/API surfaces live under https://<your-authentik-instance>/api/v3/.
In your authentik instance, create an OAuth2/OIDC provider from Applications > Applications > New Provider as documented in Create an OAuth2 provider. Request the goauthentik.io/api scope as documented in API Authentication. Use the provider's OAuth flow to mint an access token.
conventions · 0/7 published
- integrations.json——
- llms.txt✗
/llms.txt - API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing