FusionAuth integrationFusionAuth logo

FusionAuth integration for AI agents.

FusionAuth integration for AI agents with secure authentication and server-side credential injection. Open Connector runs the OAuth, seals the token in an encrypted vault, and serves FusionAuth tools to your agent over MCP or a typed API — credentials injected server-side, every call audited, nothing leaving your infrastructure. Open source (AGPL-3.0) and self-hostable.

What your agents can do

Real FusionAuth actions, managed and audited.

Your user connects FusionAuth once; your agent can then manage FusionAuth applications, users, identities, tenants, groups, email, OAuth, and authentication configuration — scoped to the OAuth permissions you grant and the tool allowlist you configure. Every action is least-privilege and written to a tamper-evident audit trail.

  1. 1

    Your user grants FusionAuth access once (OAuth) — the token lands in the vault.

  2. 2

    Your agent calls a tool over MCP or the typed API; Open Connector injects the credential server-side.

  3. 3

    Every routed call appends a hash-chained audit record — nothing leaves your infra.

Tools & triggers

Supported FusionAuth tools.

317 tools are generated from the published FusionAuth catalog. Descriptions are plain text; each action remains subject to its configured authentication and tool allowlist.

Showing 317 tools. All published catalog entries are included in this page's server-rendered HTML.

ActionUserWithId
Takes an action on a user. The user being actioned is called the "actionee" and the user taking the action is called the "actioner". Both user ids are required in the request object.
actionuserwithid
ActivateReactorWithId
Activates the FusionAuth Reactor using a license Id and optionally a license text (for air-gapped deployments)
activatereactorwithid
CancelActionWithId
Cancels the user action.
cancelactionwithid
ChangePasswordWithId
Changes a user's password using the change password Id. This usually occurs after an email has been sent to the user and they clicked on a link to reset their password. As of version 1.32.2, prefer sending the changePasswordId in the request body. To do this, omit the first parameter, and set the value in the request body.
changepasswordwithid
CommentOnUserWithId
Adds a comment to the user's account.
commentonuserwithid
CompleteVerifyIdentityWithId
Completes verification of an identity using verification codes from the Verify Start API.
completeverifyidentitywithid
CompleteWebAuthnAssertionWithId
Complete a WebAuthn authentication ceremony by validating the signature against the previously generated challenge without logging the user in
completewebauthnassertionwithid
CompleteWebAuthnLoginWithId
Complete a WebAuthn authentication ceremony by validating the signature against the previously generated challenge and then login the user in
completewebauthnloginwithid
CompleteWebAuthnRegistrationWithId
Complete a WebAuthn registration ceremony by validating the client request and saving the new credential
completewebauthnregistrationwithid
CreateApplication
Creates an application. You can optionally specify an Id for the application, if not provided one will be generated.
createapplication
CreateApplicationRole
Creates a new role for an application. You must specify the Id of the application you are creating the role for. You can optionally specify an Id for the role inside the ApplicationRole object itself, if not provided one will be generated.
createapplicationrole
CreateApplicationRoleWithId
Creates a new role for an application. You must specify the Id of the application you are creating the role for. You can optionally specify an Id for the role inside the ApplicationRole object itself, if not provided one will be generated.
createapplicationrolewithid
CreateApplicationWithId
Creates an application. You can optionally specify an Id for the application, if not provided one will be generated.
createapplicationwithid
CreateAuditLogWithId
Creates an audit log with the message and user name (usually an email). Audit logs should be written anytime you make changes to the FusionAuth database. When using the FusionAuth App web interface, any changes are automatically written to the audit log. However, if you are accessing the API, you must write the audit logs yourself.
createauditlogwithid
CreateConnector
Creates a connector. You can optionally specify an Id for the connector, if not provided one will be generated.
createconnector
CreateConnectorWithId
Creates a connector. You can optionally specify an Id for the connector, if not provided one will be generated.
createconnectorwithid
CreateConsent
Creates a user consent type. You can optionally specify an Id for the consent type, if not provided one will be generated.
createconsent
CreateConsentWithId
Creates a user consent type. You can optionally specify an Id for the consent type, if not provided one will be generated.
createconsentwithid
CreateDeviceApprove
Approve a device grant. OR Approve a device grant.
createdeviceapprove
CreateDevice Authorize
Start the Device Authorization flow using a request body OR Start the Device Authorization flow using form-encoded parameters
createdevice
CreateDeviceUserCode
Retrieve a user_code that is part of an in-progress Device Authorization Grant. This API is useful if you want to build your own login workflow to complete a device grant. OR Retrieve a user_code that is part of an in-progress Device Authorization Grant. This API is useful if you want to build your own login workflow to complete a device grant. This request will require an API key.
createdeviceusercode
CreateEmailTemplate
Creates an email template. You can optionally specify an Id for the template, if not provided one will be generated.
createemailtemplate
CreateEmailTemplateWithId
Creates an email template. You can optionally specify an Id for the template, if not provided one will be generated.
createemailtemplatewithid
CreateEntity
Creates an Entity. You can optionally specify an Id for the Entity. If not provided one will be generated.
createentity
CreateEntityType
Creates a Entity Type. You can optionally specify an Id for the Entity Type, if not provided one will be generated.
createentitytype
CreateEntityTypePermission
Creates a new permission for an entity type. You must specify the Id of the entity type you are creating the permission for. You can optionally specify an Id for the permission inside the EntityTypePermission object itself, if not provided one will be generated.
createentitytypepermission
CreateEntityTypePermissionWithId
Creates a new permission for an entity type. You must specify the Id of the entity type you are creating the permission for. You can optionally specify an Id for the permission inside the EntityTypePermission object itself, if not provided one will be generated.
createentitytypepermissionwithid
CreateEntityTypeWithId
Creates a Entity Type. You can optionally specify an Id for the Entity Type, if not provided one will be generated.
createentitytypewithid
CreateEntityWithId
Creates an Entity. You can optionally specify an Id for the Entity. If not provided one will be generated.
createentitywithid
CreateFamily
Creates a family with the user Id in the request as the owner and sole member of the family. You can optionally specify an Id for the family, if not provided one will be generated.
createfamily
CreateFamilyWithId
Creates a family with the user Id in the request as the owner and sole member of the family. You can optionally specify an Id for the family, if not provided one will be generated.
createfamilywithid
CreateForm
Creates a form. You can optionally specify an Id for the form, if not provided one will be generated.
createform
CreateFormField
Creates a form field. You can optionally specify an Id for the form, if not provided one will be generated.
createformfield
CreateFormFieldWithId
Creates a form field. You can optionally specify an Id for the form, if not provided one will be generated.
createformfieldwithid
CreateFormWithId
Creates a form. You can optionally specify an Id for the form, if not provided one will be generated.
createformwithid
CreateGroup
Creates a group. You can optionally specify an Id for the group, if not provided one will be generated.
creategroup
CreateGroupMembersWithId
Creates a member in a group.
creategroupmemberswithid
CreateGroupWithId
Creates a group. You can optionally specify an Id for the group, if not provided one will be generated.
creategroupwithid
CreateIdentityProvider
Creates an identity provider. You can optionally specify an Id for the identity provider, if not provided one will be generated.
createidentityprovider
CreateIdentityProviderWithId
Creates an identity provider. You can optionally specify an Id for the identity provider, if not provided one will be generated.
createidentityproviderwithid
CreateIntrospect
Inspect an access token issued as the result of the Client Credentials Grant. OR Inspect an access token issued as the result of the Client Credentials Grant. OR Inspect an access token issued as the result of the User based grant such as the Authorization Code Grant, Implicit Grant, the User Credentials Grant or the Refresh Grant. OR Inspect an access token issued as the result of the User based grant such as the Authorization Code Grant, Implicit Grant, the User Credentials Grant or the Refresh Grant.
createintrospect
CreateIPAccessControlList
Creates an IP Access Control List. You can optionally specify an Id on this create request, if one is not provided one will be generated.
createipaccesscontrollist
CreateIPAccessControlListWithId
Creates an IP Access Control List. You can optionally specify an Id on this create request, if one is not provided one will be generated.
createipaccesscontrollistwithid
CreateLambda
Creates a Lambda. You can optionally specify an Id for the lambda, if not provided one will be generated.
createlambda
CreateLambdaWithId
Creates a Lambda. You can optionally specify an Id for the lambda, if not provided one will be generated.
createlambdawithid
CreateLogout
The Logout API is intended to be used to remove the refresh token and access token cookies if they exist on the client and revoke the refresh token stored. This API takes the refresh token in the JSON body. OR The Logout API is intended to be used to remove the refresh token and access token cookies if they exist on the client and revoke the refresh token stored. This API does nothing if the request does not contain an access token or refresh token cookies.
createlogout
CreateMessageTemplate
Creates an message template. You can optionally specify an Id for the template, if not provided one will be generated.
createmessagetemplate
CreateMessageTemplateWithId
Creates an message template. You can optionally specify an Id for the template, if not provided one will be generated.
createmessagetemplatewithid
CreateMessenger
Creates a messenger. You can optionally specify an Id for the messenger, if not provided one will be generated.
createmessenger
CreateMessengerWithId
Creates a messenger. You can optionally specify an Id for the messenger, if not provided one will be generated.
createmessengerwithid
CreateOAuthScope
Creates a new custom OAuth scope for an application. You must specify the Id of the application you are creating the scope for. You can optionally specify an Id for the OAuth scope on the URL, if not provided one will be generated.
createoauthscope
CreateOAuthScopeWithId
Creates a new custom OAuth scope for an application. You must specify the Id of the application you are creating the scope for. You can optionally specify an Id for the OAuth scope on the URL, if not provided one will be generated.
createoauthscopewithid
CreateTenant
Creates a tenant. You can optionally specify an Id for the tenant, if not provided one will be generated.
createtenant
CreateTenantManagerIdentityProviderTypeConfigurationWithId
Creates a tenant manager identity provider type configuration for the given identity provider type.
createtenantmanageridentityprovidertypeconfigurationwithid
CreateTenantWithId
Creates a tenant. You can optionally specify an Id for the tenant, if not provided one will be generated.
createtenantwithid
CreateTheme
Creates a Theme. You can optionally specify an Id for the theme, if not provided one will be generated.
createtheme
CreateThemeWithId
Creates a Theme. You can optionally specify an Id for the theme, if not provided one will be generated.
createthemewithid
CreateToken
Exchange User Credentials for a Token. If you will be using the Resource Owner Password Credential Grant, you will make a request to the Token endpoint to exchange the user’s email and password for an access token. OR Exchange User Credentials for a Token. If you will be using the Resource Owner Password Credential Grant, you will make a request to the Token endpoint to exchange the user’s email and password for an access token. OR Exchange a Refresh Token for an Access Token. If you will be using the Refresh Token Grant, you will make a request to the Token endpoint to exchange the user’s refresh token for an access token. OR Exchange a Refresh Token for an Access Token. If you will be using the Refresh Token Grant, you will make a request to the Token endpoint to exchange the user’s refresh token for an access token. OR Exchanges an OAuth authorization code for an access token. Makes a request to the Token endpoint to exchange the authorization code returned from the Authorize endpoint for an access token. OR Exchanges an OAuth authorization code and code_verifier for an access token. Makes a request to the Token endpoint to exchange the authorization code returned from the Authorize endpoint and a code_verifier for an access token. OR Exchanges an OAuth authorization code and code_verifier for an access token. Makes a request to the Token endpoint to exchange the authorization code returned from the Authorize endpoint and a code_verifier for an access token. OR Exchanges an OAuth authorization code for an access token. Makes a request to the Token endpoint to exchange the authorization code returned from the Authorize endpoint for an access token. OR Make a Client Credentials grant request to obtain an access token. OR Make a Client Credentials grant request to obtain an access token.
createtoken
CreateUser
Creates a user. You can optionally specify an Id for the user, if not provided one will be generated.
createuser
CreateUserAction
Creates a user action. This action cannot be taken on a user until this call successfully returns. Anytime after that the user action can be applied to any user.
createuseraction
CreateUserActionReason
Creates a user reason. This user action reason cannot be used when actioning a user until this call completes successfully. Anytime after that the user action reason can be used.
createuseractionreason
CreateUserActionReasonWithId
Creates a user reason. This user action reason cannot be used when actioning a user until this call completes successfully. Anytime after that the user action reason can be used.
createuseractionreasonwithid
CreateUserActionWithId
Creates a user action. This action cannot be taken on a user until this call successfully returns. Anytime after that the user action can be applied to any user.
createuseractionwithid
CreateUserChangePassword
Changes a user's password using their access token (JWT) instead of the changePasswordId A common use case for this method will be if you want to allow the user to change their own password. Remember to send refreshToken in the request body if you want to get a new refresh token when login using the returned oneTimePassword. OR Changes a user's password using their identity (loginId and password). Using a loginId instead of the changePasswordId bypasses the email verification and allows a password to be changed directly without first calling the #forgotPassword method.
createuserchangepassword
CreateUserConsent
Creates a single User consent.
createuserconsent
CreateUserConsentWithId
Creates a single User consent.
createuserconsentwithid
CreateUserLinkWithId
Link an external user from a 3rd party identity provider to a FusionAuth user.
createuserlinkwithid
CreateUserVerifyEmail
Administratively verify a user's email address. Use this method to bypass email verification for the user. The request body will contain the userId to be verified. An API key is required when sending the userId in the request body. OR Confirms a user's email address. The request body will contain the verificationId. You may also be required to send a one-time use code based upon your configuration. When the tenant is configured to gate a user until their email address is verified, this procedures requires two values instead of one. The verificationId is a high entropy value and the one-time use code is a low entropy value that is easily entered in a user interactive form. The two values together are able to confirm a user's email address and mark the user's email address as verified.
createuserverifyemail
CreateUserWithId
Creates a user. You can optionally specify an Id for the user, if not provided one will be generated.
createuserwithid
CreateWebhook
Creates a webhook. You can optionally specify an Id for the webhook, if not provided one will be generated.
createwebhook
CreateWebhookWithId
Creates a webhook. You can optionally specify an Id for the webhook, if not provided one will be generated.
createwebhookwithid
DeleteApplicationRoleWithId
Hard deletes an application role. This is a dangerous operation and should not be used in most circumstances. This permanently removes the given role from all users that had it.
deleteapplicationrolewithid
DeleteApplicationWithId
Hard deletes an application. This is a dangerous operation and should not be used in most circumstances. This will delete the application, any registrations for that application, metrics and reports for the application, all the roles for the application, and any other data associated with the application. This operation could take a very long time, depending on the amount of data in your database. OR Deactivates the application with the given Id.
deleteapplicationwithid
DeleteConnectorWithId
Deletes the connector for the given Id.
deleteconnectorwithid
DeleteConsentWithId
Deletes the consent for the given Id.
deleteconsentwithid
DeleteEmailTemplateWithId
Deletes the email template for the given Id.
deleteemailtemplatewithid
DeleteEntityGrantWithId
Deletes an Entity Grant for the given User or Entity.
deleteentitygrantwithid
DeleteEntityTypePermissionWithId
Hard deletes a permission. This is a dangerous operation and should not be used in most circumstances. This permanently removes the given permission from all grants that had it.
deleteentitytypepermissionwithid
DeleteEntityTypeWithId
Deletes the Entity Type for the given Id.
deleteentitytypewithid
DeleteEntityWithId
Deletes the Entity for the given Id.
deleteentitywithid
DeleteFormFieldWithId
Deletes the form field for the given Id.
deleteformfieldwithid
DeleteFormWithId
Deletes the form for the given Id.
deleteformwithid
DeleteGroupMembersWithId
Removes users as members of a group.
deletegroupmemberswithid
DeleteGroupWithId
Deletes the group for the given Id.
deletegroupwithid
DeleteIdentityProviderWithId
Deletes the identity provider for the given Id.
deleteidentityproviderwithid
DeleteIPAccessControlListWithId
Deletes the IP Access Control List for the given Id.
deleteipaccesscontrollistwithid
DeleteJwtRefresh
Revokes refresh tokens using the information in the JSON body. The handling for this method is the same as the revokeRefreshToken method and is based on the information you provide in the RefreshDeleteRequest object. See that method for additional information. OR Revoke all refresh tokens that belong to a user by user Id for a specific application by applicationId. OR Revoke all refresh tokens that belong to a user by user Id. OR Revoke all refresh tokens that belong to an application by applicationId. OR Revokes a single refresh token by using the actual refresh token value. This refresh token value is sensitive, so be careful with this API request. OR Revokes refresh tokens. Usage examples: - Delete a single refresh token, pass in only the token. revokeRefreshToken(token) - Delete all refresh tokens for a user, pass in only the userId. revokeRefreshToken(null, userId) - Delete all refresh tokens for a user for a specific application, pass in both the userId and the applicationId. revokeRefreshToken(null, userId, applicationId) - Delete all refresh tokens for an application revokeRefreshToken(null, null, applicationId) Note: <code>null</code> may be handled differently depending upon the programming language. See also: (method names may vary by language... but you'll figure it out) - revokeRefreshTokenById - revokeRefreshTokenByToken - revokeRefreshTokensByUserId - revokeRefreshTokensByApplicationId - revokeRefreshTokensByUserIdForApplication
deletejwtrefresh
DeleteKeyWithId
Deletes the key for the given Id.
deletekeywithid
DeleteLambdaWithId
Deletes the lambda for the given Id.
deletelambdawithid
DeleteMessageTemplateWithId
Deletes the message template for the given Id.
deletemessagetemplatewithid
DeleteMessengerWithId
Deletes the messenger for the given Id.
deletemessengerwithid
DeleteOAuthScopeWithId
Hard deletes a custom OAuth scope. OAuth workflows that are still requesting the deleted OAuth scope may fail depending on the application's unknown scope policy.
deleteoauthscopewithid
DeleteTenantManagerIdentityProviderTypeConfigurationWithId
Deletes the tenant manager identity provider type configuration for the given identity provider type.
deletetenantmanageridentityprovidertypeconfigurationwithid
DeleteTenantWithId
Deletes the tenant based on the given request (sent to the API as JSON). This permanently deletes all information, metrics, reports and data associated with the tenant and everything under the tenant (applications, users, etc). OR Deletes the tenant for the given Id asynchronously. This method is helpful if you do not want to wait for the delete operation to complete. OR Deletes the tenant based on the given Id on the URL. This permanently deletes all information, metrics, reports and data associated with the tenant and everything under the tenant (applications, users, etc).
deletetenantwithid
DeleteThemeWithId
Deletes the theme for the given Id.
deletethemewithid
DeleteUserActionReasonWithId
Deletes the user action reason for the given Id.
deleteuseractionreasonwithid
DeleteUserActionWithId
Deletes the user action for the given Id. This permanently deletes the user action and also any history and logs of the action being applied to any users. OR Deactivates the user action with the given Id.
deleteuseractionwithid
DeleteUserBulk
Deletes the users with the given Ids, or users matching the provided JSON query or queryString. The order of preference is Ids, query and then queryString, it is recommended to only provide one of the three for the request. This method can be used to deactivate or permanently delete (hard-delete) users based upon the hardDelete boolean in the request body. Using the dryRun parameter you may also request the result of the action without actually deleting or deactivating any users. OR Deactivates the users with the given Ids.
deleteuserbulk
DeleteUserLinkWithId
Remove an existing link that has been made from a 3rd party identity provider to a FusionAuth user.
deleteuserlinkwithid
DeleteUserRegistrationWithId
Deletes the user registration for the given user and application along with the given JSON body that contains the event information. OR Deletes the user registration for the given user and application.
deleteuserregistrationwithid
DeleteUserTwoFactorWithId
Disable two-factor authentication for a user using a JSON body rather than URL parameters. OR Disable two-factor authentication for a user.
deleteusertwofactorwithid
DeleteUserWithId
Deletes the user based on the given request (sent to the API as JSON). This permanently deletes all information, metrics, reports and data associated with the user. OR Deletes the user for the given Id. This permanently deletes all information, metrics, reports and data associated with the user. OR Deactivates the user with the given Id.
deleteuserwithid
DeleteWebAuthnCredentialWithId
Deletes the WebAuthn credential for the given Id.
deletewebauthncredentialwithid
DeleteWebAuthnCredentialsForUserWithId
Deletes all of the WebAuthn credentials for the given User Id.
deletewebauthncredentialsforuserwithid
DeleteWebhookWithId
Deletes the webhook for the given Id.
deletewebhookwithid
EnableTwoFactorWithId
Enable two-factor authentication for a user.
enabletwofactorwithid
ExchangeRefreshTokenForJWTWithId
Exchange a refresh token for a new JWT.
exchangerefreshtokenforjwtwithid
ForgotPasswordWithId
Begins the forgot password sequence, which kicks off an email to the user so that they can reset their password.
forgotpasswordwithid
GenerateKey
Generate a new RSA or EC key pair or an HMAC secret.
generatekey
GenerateKeyWithId
Generate a new RSA or EC key pair or an HMAC secret.
generatekeywithid
GenerateTwoFactorRecoveryCodesWithId
Generate two-factor recovery codes for a user. Generating two-factor recovery codes will invalidate any existing recovery codes.
generatetwofactorrecoverycodeswithid
GenerateTwoFactorSecretUsingJWTWithId
Generate a Two Factor secret that can be used to enable Two Factor authentication for a User. The response will contain both the secret and a Base32 encoded form of the secret which can be shown to a User when using a 2 Step Authentication application such as Google Authenticator.
generatetwofactorsecretusingjwtwithid
IdentityProviderLoginWithId
Handles login via third-parties including Social login, external OAuth and OpenID Connect, and other login systems.
identityproviderloginwithid
ImportKey
Import an existing RSA or EC key pair or an HMAC secret.
importkey
ImportKeyWithId
Import an existing RSA or EC key pair or an HMAC secret.
importkeywithid
ImportRefreshTokensWithId
Bulk imports refresh tokens. This request performs minimal validation and runs batch inserts of refresh tokens with the expectation that each token represents a user that already exists and is registered for the corresponding FusionAuth Application. This is done to increases the insert performance. Therefore, if you encounter an error due to a database key violation, the response will likely offer a generic explanation. If you encounter an error, you may optionally enable additional validation to receive a JSON response body with specific validation errors. This will slow the request down but will allow you to identify the cause of the failure. See the validateDbConstraints request parameter.
importrefreshtokenswithid
ImportUsersWithId
Bulk imports users. This request performs minimal validation and runs batch inserts of users with the expectation that each user does not yet exist and each registration corresponds to an existing FusionAuth Application. This is done to increases the insert performance. Therefore, if you encounter an error due to a database key violation, the response will likely offer a generic explanation. If you encounter an error, you may optionally enable additional validation to receive a JSON response body with specific validation errors. This will slow the request down but will allow you to identify the cause of the failure. See the validateDbConstraints request parameter.
importuserswithid
ImportWebAuthnCredentialWithId
Import a WebAuthn credential
importwebauthncredentialwithid
IssueJWTWithId
Issue a new access token (JWT) for the requested Application after ensuring the provided JWT is valid. A valid access token is properly signed and not expired. <p> This API may be used in an SSO configuration to issue new tokens for another application after the user has obtained a valid token from authentication.
issuejwtwithid
LoginPingWithId
Sends a ping to FusionAuth indicating that the user was automatically logged into an application. When using FusionAuth's SSO or your own, you should call this if the user is already logged in centrally, but accesses an application where they no longer have a session. This helps correctly track login counts, times and helps with reporting.
loginpingwithid
LoginPingWithRequestWithId
Sends a ping to FusionAuth indicating that the user was automatically logged into an application. When using FusionAuth's SSO or your own, you should call this if the user is already logged in centrally, but accesses an application where they no longer have a session. This helps correctly track login counts, times and helps with reporting.
loginpingwithrequestwithid
LoginWithId
Authenticates a user to FusionAuth. This API optionally requires an API key. See <code>Application.loginConfiguration.requireAuthentication</code>.
loginwithid
ModifyActionWithId
Modifies a temporal user action by changing the expiration of the action and optionally adding a comment to the action.
modifyactionwithid
PasswordlessLoginWithId
Complete a login request using a passwordless code
passwordlessloginwithid
PatchApplicationRoleWithId
Updates, via PATCH, the application role with the given Id for the application.
patchapplicationrolewithid
PatchApplicationWithId
Updates, via PATCH, the application with the given Id.
patchapplicationwithid
PatchConnectorWithId
Updates, via PATCH, the connector with the given Id.
patchconnectorwithid
PatchConsentWithId
Updates, via PATCH, the consent with the given Id.
patchconsentwithid
PatchEmailTemplateWithId
Updates, via PATCH, the email template with the given Id.
patchemailtemplatewithid
PatchEntityTypePermissionWithId
Patches the permission with the given Id for the entity type.
patchentitytypepermissionwithid
PatchEntityTypeWithId
Updates, via PATCH, the Entity Type with the given Id.
patchentitytypewithid
PatchEntityWithId
Updates, via PATCH, the Entity with the given Id.
patchentitywithid
PatchFormFieldWithId
Patches the form field with the given Id.
patchformfieldwithid
PatchFormWithId
Patches the form with the given Id.
patchformwithid
PatchGroupWithId
Updates, via PATCH, the group with the given Id.
patchgroupwithid
PatchIdentityProviderWithId
Updates, via PATCH, the identity provider with the given Id.
patchidentityproviderwithid
PatchIntegrationsWithId
Updates, via PATCH, the available integrations.
patchintegrationswithid
PatchIPAccessControlListWithId
Update the IP Access Control List with the given Id.
patchipaccesscontrollistwithid
PatchLambdaWithId
Updates, via PATCH, the lambda with the given Id.
patchlambdawithid
PatchMessageTemplateWithId
Updates, via PATCH, the message template with the given Id.
patchmessagetemplatewithid
PatchMessengerWithId
Updates, via PATCH, the messenger with the given Id.
patchmessengerwithid
PatchOAuthScopeWithId
Updates, via PATCH, the custom OAuth scope with the given Id for the application.
patchoauthscopewithid
PatchRegistrationWithId
Updates, via PATCH, the registration for the user with the given Id and the application defined in the request.
patchregistrationwithid
PatchSystemConfigurationWithId
Updates, via PATCH, the system configuration.
patchsystemconfigurationwithid
PatchTenantManagerConfigurationWithId
Updates, via PATCH, the Tenant Manager configuration.
patchtenantmanagerconfigurationwithid
PatchTenantManagerIdentityProviderTypeConfigurationWithId
Patches the tenant manager identity provider type configuration for the given identity provider type.
patchtenantmanageridentityprovidertypeconfigurationwithid
PatchTenantWithId
Updates, via PATCH, the tenant with the given Id.
patchtenantwithid
PatchThemeWithId
Updates, via PATCH, the theme with the given Id.
patchthemewithid
PatchUserActionReasonWithId
Updates, via PATCH, the user action reason with the given Id.
patchuseractionreasonwithid
PatchUserActionWithId
Updates, via PATCH, the user action with the given Id.
patchuseractionwithid
PatchUserConsentWithId
Updates, via PATCH, a single User consent by Id.
patchuserconsentwithid
PatchUserWithId
Updates, via PATCH, the user with the given Id.
patchuserwithid
PatchWebhookWithId
Patches the webhook with the given Id.
patchwebhookwithid
ReconcileJWTWithId
Reconcile a User to FusionAuth using JWT issued from another Identity Provider.
reconcilejwtwithid
Register
Registers a user for an application. If you provide the User and the UserRegistration object on this request, it will create the user as well as register them for the application. This is called a Full Registration. However, if you only provide the UserRegistration object, then the user must already exist and they will be registered for the application. The user Id can also be provided and it will either be used to look up an existing user or it will be used for the newly created User.
register
RegisterWithId
Registers a user for an application. If you provide the User and the UserRegistration object on this request, it will create the user as well as register them for the application. This is called a Full Registration. However, if you only provide the UserRegistration object, then the user must already exist and they will be registered for the application. The user Id can also be provided and it will either be used to look up an existing user or it will be used for the newly created User.
registerwithid
ReindexWithId
Requests Elasticsearch to delete and rebuild the index for FusionAuth users or entities. Be very careful when running this request as it will increase the CPU and I/O load on your database until the operation completes. Generally speaking you do not ever need to run this operation unless instructed by FusionAuth support, or if you are migrating a database another system and you are not brining along the Elasticsearch index. You have been warned.
reindexwithid
RemoveUserFromFamilyWithId
Removes a user from the family with the given Id.
removeuserfromfamilywithid
RetrieveActionWithId
Retrieves a single action log (the log of a user action that was taken on a user previously) for the given Id.
retrieveactionwithid
RetrieveApplication
Retrieves all the applications that are currently inactive. OR Retrieves the application for the given Id or all the applications if the Id is null.
retrieveapplication
RetrieveApplicationWithId
Retrieves the application for the given Id or all the applications if the Id is null.
retrieveapplicationwithid
RetrieveAuditLogWithId
Retrieves a single audit log for the given Id.
retrieveauditlogwithid
RetrieveConnectorWithId
Retrieves the connector with the given Id.
retrieveconnectorwithid
RetrieveConsentWithId
Retrieves the Consent for the given Id.
retrieveconsentwithid
RetrieveDailyActiveReportWithId
Retrieves the daily active user report between the two instants. If you specify an application Id, it will only return the daily active counts for that application.
retrievedailyactivereportwithid
RetrieveDeviceUserCode
Retrieve a user_code that is part of an in-progress Device Authorization Grant. This API is useful if you want to build your own login workflow to complete a device grant. This request will require an API key. OR Retrieve a user_code that is part of an in-progress Device Authorization Grant. This API is useful if you want to build your own login workflow to complete a device grant.
retrievedeviceusercode
RetrieveDeviceValidate
Validates the end-user provided user_code from the user-interaction of the Device Authorization Grant. If you build your own activation form you should validate the user provided code prior to beginning the Authorization grant. OR Validates the end-user provided user_code from the user-interaction of the Device Authorization Grant. If you build your own activation form you should validate the user provided code prior to beginning the Authorization grant.
retrievedevicevalidate
RetrieveEmailTemplate
Retrieves the email template for the given Id. If you don't specify the Id, this will return all the email templates.
retrieveemailtemplate
RetrieveEmailTemplatePreviewWithId
Creates a preview of the email template provided in the request. This allows you to preview an email template that hasn't been saved to the database yet. The entire email template does not need to be provided on the request. This will create the preview based on whatever is given.
retrieveemailtemplatepreviewwithid
RetrieveEmailTemplateWithId
Retrieves the email template for the given Id. If you don't specify the Id, this will return all the email templates.
retrieveemailtemplatewithid
RetrieveEntityGrantWithId
Retrieves an Entity Grant for the given Entity and User/Entity.
retrieveentitygrantwithid
RetrieveEntityTypeWithId
Retrieves the Entity Type for the given Id.
retrieveentitytypewithid
RetrieveEntityWithId
Retrieves the Entity for the given Id.
retrieveentitywithid
RetrieveEventLogWithId
Retrieves a single event log for the given Id.
retrieveeventlogwithid
RetrieveFamiliesWithId
Retrieves all the families that a user belongs to.
retrievefamilieswithid
RetrieveFamilyMembersByFamilyIdWithId
Retrieves all the members of a family by the unique Family Id.
retrievefamilymembersbyfamilyidwithid
RetrieveFormFieldWithId
Retrieves the form field with the given Id.
retrieveformfieldwithid
RetrieveFormWithId
Retrieves the form with the given Id.
retrieveformwithid
RetrieveGroupWithId
Retrieves the group for the given Id.
retrievegroupwithid
RetrieveIdentityProviderByTypeWithId
Retrieves one or more identity provider for the given type. For types such as Google, Facebook, Twitter and LinkedIn, only a single identity provider can exist. For types such as OpenID Connect and SAMLv2 more than one identity provider can be configured so this request may return multiple identity providers.
retrieveidentityproviderbytypewithid
RetrieveIdentityProviderConnectionTestResultsWithId
Retrieves the results for an identity provider connection test.
retrieveidentityproviderconnectiontestresultswithid
RetrieveIdentityProviderLink
Retrieve all Identity Provider users (links) for the user. Specify the optional identityProviderId to retrieve links for a particular IdP. OR Retrieve a single Identity Provider user (link).
retrieveidentityproviderlink
RetrieveIdentityProviderLookup
Retrieves the identity provider for the given domain and tenantId. A 200 response code indicates the domain is managed by a registered identity provider. A 404 indicates the domain is not managed. OR Retrieves any global identity providers for the given domain. A 200 response code indicates the domain is managed by a registered identity provider. A 404 indicates the domain is not managed.
retrieveidentityproviderlookup
RetrieveIdentityProviderWithId
Retrieves the identity provider for the given Id or all the identity providers if the Id is null.
retrieveidentityproviderwithid
RetrieveIPAccessControlListWithId
Retrieves the IP Access Control List with the given Id.
retrieveipaccesscontrollistwithid
RetrieveJsonWebKeySetWithId
Returns public keys used by FusionAuth to cryptographically verify JWTs using the JSON Web Key format.
retrievejsonwebkeysetwithid
RetrieveJwtPublicKey
Retrieves the Public Key configured for verifying the JSON Web Tokens (JWT) issued by the Login API by the Application Id. OR Retrieves the Public Key configured for verifying JSON Web Tokens (JWT) by the key Id (kid).
retrievejwtpublickey
RetrieveKeyWithId
Retrieves the key for the given Id.
retrievekeywithid
RetrieveKeysWithId
Retrieves all the keys.
retrievekeyswithid
RetrieveLambdaWithId
Retrieves the lambda for the given Id.
retrievelambdawithid
RetrieveLambdasByTypeWithId
Retrieves all the lambdas for the provided type.
retrievelambdasbytypewithid
RetrieveMessageTemplate
Retrieves the message template for the given Id. If you don't specify the Id, this will return all the message templates.
retrievemessagetemplate
RetrieveMessageTemplatePreviewWithId
Creates a preview of the message template provided in the request, normalized to a given locale.
retrievemessagetemplatepreviewwithid
RetrieveMessageTemplateWithId
Retrieves the message template for the given Id. If you don't specify the Id, this will return all the message templates.
retrievemessagetemplatewithid
RetrieveMessengerWithId
Retrieves the messenger with the given Id.
retrievemessengerwithid
RetrieveMonthlyActiveReportWithId
Retrieves the monthly active user report between the two instants. If you specify an application Id, it will only return the monthly active counts for that application.
retrievemonthlyactivereportwithid
RetrieveOauthConfigurationWithId
Retrieves the Oauth2 configuration for the application for the given Application Id.
retrieveoauthconfigurationwithid
RetrieveOAuthScopeWithId
Retrieves a custom OAuth scope.
retrieveoauthscopewithid
RetrieveOpenIdConfigurationWithId
Returns the well known OpenID Configuration JSON document
retrieveopenidconfigurationwithid
RetrievePasswordValidationRulesWithId
Retrieves the password validation rules for a specific tenant. This method requires a tenantId to be provided through the use of a Tenant scoped API key or an HTTP header X-FusionAuth-TenantId to specify the Tenant Id. This API does not require an API key.
retrievepasswordvalidationruleswithid
RetrievePasswordValidationRulesWithTenantIdWithId
Retrieves the password validation rules for a specific tenant. This API does not require an API key.
retrievepasswordvalidationruleswithtenantidwithid
RetrievePendingChildrenWithId
Retrieves all the children for the given parent email address.
retrievependingchildrenwithid
RetrievePendingLinkWithId
Retrieve a pending identity provider link. This is useful to validate a pending link and retrieve meta-data about the identity provider link.
retrievependinglinkwithid
RetrieveReactorMetricsWithId
Retrieves the FusionAuth Reactor metrics.
retrievereactormetricswithid
RetrieveRefreshTokenByIdWithId
Retrieves a single refresh token by unique Id. This is not the same thing as the string value of the refresh token. If you have that, you already have what you need.
retrieverefreshtokenbyidwithid
RetrieveRefreshTokensWithId
Retrieves the refresh tokens that belong to the user with the given Id.
retrieverefreshtokenswithid
RetrieveRegistrationReportWithId
Retrieves the registration report between the two instants. If you specify an application Id, it will only return the registration counts for that application.
retrieveregistrationreportwithid
RetrieveRegistrationWithId
Retrieves the user registration for the user with the given Id and the given application Id.
retrieveregistrationwithid
RetrieveReportLogin
Retrieves the login report between the two instants for a particular user by login Id, using specific loginIdTypes. If you specify an application id, it will only return the login counts for that application. OR Retrieves the login report between the two instants for a particular user by login Id. If you specify an application Id, it will only return the login counts for that application. OR Retrieves the login report between the two instants for a particular user by Id. If you specify an application Id, it will only return the login counts for that application. OR Retrieves the login report between the two instants. If you specify an application Id, it will only return the login counts for that application.
retrievereportlogin
RetrieveStatus
Retrieves the FusionAuth system status using an API key. Using an API key will cause the response to include the product version, health checks and various runtime metrics. OR Retrieves the FusionAuth system status. This request is anonymous and does not require an API key. When an API key is not provided the response will contain a single value in the JSON response indicating the current health check.
retrievestatus
RetrieveSystemHealthWithId
Retrieves the FusionAuth system health. This API will return 200 if the system is healthy, and 500 if the system is un-healthy.
retrievesystemhealthwithid
RetrieveTenantWithId
Retrieves the tenant for the given Id.
retrievetenantwithid
RetrieveThemeWithId
Retrieves the theme for the given Id.
retrievethemewithid
RetrieveTotalReportWithExcludesWithId
Retrieves the totals report. This allows excluding applicationTotals from the report. An empty list will include the applicationTotals.
retrievetotalreportwithexcludeswithid
RetrieveTwoFactorRecoveryCodesWithId
Retrieve two-factor recovery codes for a user.
retrievetwofactorrecoverycodeswithid
RetrieveTwoFactorStatusWithId
Retrieve a user's two-factor status. This can be used to see if a user will need to complete a two-factor challenge to complete a login, and optionally identify the state of the two-factor trust across various applications.
retrievetwofactorstatuswithid
RetrieveTwoFactorStatusWithRequestWithId
Retrieve a user's two-factor status. This can be used to see if a user will need to complete a two-factor challenge to complete a login, and optionally identify the state of the two-factor trust across various applications. This operation provides more payload options than retrieveTwoFactorStatus.
retrievetwofactorstatuswithrequestwithid
RetrieveUser
Retrieves the user by a verificationId. The intended use of this API is to retrieve a user after the forgot password workflow has been initiated and you may not know the user's email or username. OR Retrieves the user for the given username. OR Retrieves the user for the loginId, using specific loginIdTypes. OR Retrieves the user for the loginId. The loginId can be either the username or the email. OR Retrieves the user for the given email. OR Retrieves the user by a change password Id. The intended use of this API is to retrieve a user after the forgot password workflow has been initiated and you may not know the user's email or username.
retrieveuser
RetrieveUserAction
Retrieves the user action for the given Id. If you pass in null for the Id, this will return all the user actions. OR Retrieves all the user actions that are currently inactive.
retrieveuseraction
RetrieveUserActionReason
Retrieves the user action reason for the given Id. If you pass in null for the Id, this will return all the user action reasons.
retrieveuseractionreason
RetrieveUserActionReasonWithId
Retrieves the user action reason for the given Id. If you pass in null for the Id, this will return all the user action reasons.
retrieveuseractionreasonwithid
RetrieveUserActionWithId
Retrieves the user action for the given Id. If you pass in null for the Id, this will return all the user actions.
retrieveuseractionwithid
RetrieveUserActioning
Retrieves all the actions for the user with the given Id that are currently inactive. An inactive action means one that is time based and has been canceled or has expired, or is not time based. OR Retrieves all the actions for the user with the given Id that are currently active. An active action means one that is time based and has not been canceled, and has not ended. OR Retrieves all the actions for the user with the given Id that are currently preventing the User from logging in. OR Retrieves all the actions for the user with the given Id. This will return all time based actions that are active, and inactive as well as non-time based actions.
retrieveuseractioning
RetrieveUserChangePassword
Check to see if the user must obtain a Trust Request Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Request Id by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API. OR Check to see if the user must obtain a Trust Request Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Request Id by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API. OR Check to see if the user must obtain a Trust Request Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Request Id by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API. OR Check to see if the user must obtain a Trust Request Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Request Id by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API. OR Check to see if the user must obtain a Trust Token Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Token by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API. OR Check to see if the user must obtain a Trust Token Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Token by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API.
retrieveuserchangepassword
RetrieveUserChangePasswordWithId
Check to see if the user must obtain a Trust Token Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Token by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API. OR Check to see if the user must obtain a Trust Token Id in order to complete a change password request. When a user has enabled Two-Factor authentication, before you are allowed to use the Change Password API to change your password, you must obtain a Trust Token by completing a Two-Factor Step-Up authentication. An HTTP status code of 400 with a general error code of [TrustTokenRequired] indicates that a Trust Token is required to make a POST request to this API.
retrieveuserchangepasswordwithid
RetrieveUserCommentsWithId
Retrieves all the comments for the user with the given Id.
retrieveusercommentswithid
RetrieveUserConsentWithId
Retrieve a single User consent by Id.
retrieveuserconsentwithid
RetrieveUserConsentsWithId
Retrieves all the consents for a User.
retrieveuserconsentswithid
RetrieveUserInfoFromAccessTokenWithId
Call the UserInfo endpoint to retrieve User Claims from the access token issued by FusionAuth.
retrieveuserinfofromaccesstokenwithid
RetrieveUserRecentLogin
Retrieves the last number of login records for a user. OR Retrieves the last number of login records.
retrieveuserrecentlogin
RetrieveUserWithId
Retrieves the user for the given Id.
retrieveuserwithid
RetrieveVersionWithId
Retrieves the FusionAuth version string.
retrieveversionwithid
RetrieveWebAuthnCredentialWithId
Retrieves the WebAuthn credential for the given Id.
retrievewebauthncredentialwithid
RetrieveWebAuthnCredentialsForUserWithId
Retrieves all WebAuthn credentials for the given user.
retrievewebauthncredentialsforuserwithid
RetrieveWebhook
Retrieves the webhook for the given Id. If you pass in null for the Id, this will return all the webhooks.
retrievewebhook
RetrieveWebhookAttemptLogWithId
Retrieves a single webhook attempt log for the given Id.
retrievewebhookattemptlogwithid
RetrieveWebhookEventLogWithId
Retrieves a single webhook event log for the given Id.
retrievewebhookeventlogwithid
RetrieveWebhookWithId
Retrieves the webhook for the given Id. If you pass in null for the Id, this will return all the webhooks.
retrievewebhookwithid
RevokeRefreshTokenByIdWithId
Revokes a single refresh token by the unique Id. The unique Id is not sensitive as it cannot be used to obtain another JWT.
revokerefreshtokenbyidwithid
RevokeUserConsentWithId
Revokes a single User consent by Id.
revokeuserconsentwithid
SearchApplicationsWithId
Searches applications with the specified criteria and pagination.
searchapplicationswithid
SearchAuditLogsWithId
Searches the audit logs with the specified criteria and pagination.
searchauditlogswithid
SearchConsentsWithId
Searches consents with the specified criteria and pagination.
searchconsentswithid
SearchEmailTemplatesWithId
Searches email templates with the specified criteria and pagination.
searchemailtemplateswithid
SearchEntitiesByIdsWithId
Retrieves the entities for the given Ids. If any Id is invalid, it is ignored.
searchentitiesbyidswithid
SearchEntitiesWithId
Searches entities with the specified criteria and pagination.
searchentitieswithid
SearchEntityGrantsWithId
Searches Entity Grants with the specified criteria and pagination.
searchentitygrantswithid
SearchEntityTypesWithId
Searches the entity types with the specified criteria and pagination.
searchentitytypeswithid
SearchEventLogsWithId
Searches the event logs with the specified criteria and pagination.
searcheventlogswithid
SearchGroupMembersWithId
Searches group members with the specified criteria and pagination.
searchgroupmemberswithid
SearchGroupsWithId
Searches groups with the specified criteria and pagination.
searchgroupswithid
SearchIdentityProvidersWithId
Searches identity providers with the specified criteria and pagination.
searchidentityproviderswithid
SearchIPAccessControlListsWithId
Searches the IP Access Control Lists with the specified criteria and pagination.
searchipaccesscontrollistswithid
SearchKeysWithId
Searches keys with the specified criteria and pagination.
searchkeyswithid
SearchLambdasWithId
Searches lambdas with the specified criteria and pagination.
searchlambdaswithid
SearchLoginRecordsWithId
Searches the login records with the specified criteria and pagination.
searchloginrecordswithid
SearchTenantsWithId
Searches tenants with the specified criteria and pagination.
searchtenantswithid
SearchThemesWithId
Searches themes with the specified criteria and pagination.
searchthemeswithid
SearchUserCommentsWithId
Searches user comments with the specified criteria and pagination.
searchusercommentswithid
SearchUsersByIdsWithId
Retrieves the users for the given Ids. If any Id is invalid, it is ignored.
searchusersbyidswithid
SearchUsersByQueryWithId
Retrieves the users for the given search criteria and pagination.
searchusersbyquerywithid
SearchWebhookEventLogsWithId
Searches the webhook event logs with the specified criteria and pagination.
searchwebhookeventlogswithid
SearchWebhooksWithId
Searches webhooks with the specified criteria and pagination.
searchwebhookswithid
SendEmailWithId
Send an email using an email template Id. You can optionally provide <code>requestData</code> to access key value pairs in the email template.
sendemailwithid
SendFamilyRequestEmailWithId
Sends out an email to a parent that they need to register and create a family or need to log in and add a child to their existing family.
sendfamilyrequestemailwithid
SendPasswordlessCodeWithId
Send a passwordless authentication code in an email to complete login.
sendpasswordlesscodewithid
SendTwoFactorCodeForEnableDisableWithId
Send a Two Factor authentication code to assist in setting up Two Factor authentication or disabling.
sendtwofactorcodeforenabledisablewithid
SendTwoFactorCodeForLoginUsingMethodWithId
Send a Two Factor authentication code to allow the completion of Two Factor authentication.
sendtwofactorcodeforloginusingmethodwithid
SendVerifyIdentityWithId
Send a verification code using the appropriate transport for the identity type being verified.
sendverifyidentitywithid
StartIdentityProviderConnectionTestWithId
Begins an identity provider connection test.
startidentityproviderconnectiontestwithid
StartIdentityProviderLoginWithId
Begins a login request for a 3rd party login that requires user interaction such as HYPR.
startidentityproviderloginwithid
StartPasswordlessLoginWithId
Start a passwordless login request by generating a passwordless code. This code can be sent to the User using the Send Passwordless Code API or using a mechanism outside of FusionAuth. The passwordless login is completed by using the Passwordless Login API with this code.
startpasswordlessloginwithid
StartTwoFactorLoginWithId
Start a Two-Factor login request by generating a two-factor identifier. This code can then be sent to the Two Factor Send API (/api/two-factor/send)in order to send a one-time use code to a user. You can also use one-time use code returned to send the code out-of-band. The Two-Factor login is completed by making a request to the Two-Factor Login API (/api/two-factor/login). with the two-factor identifier and the one-time use code. This API is intended to allow you to begin a Two-Factor login outside a normal login that originated from the Login API (/api/login).
starttwofactorloginwithid
StartVerifyIdentityWithId
Start a verification of an identity by generating a code. This code can be sent to the User using the Verify Send API Verification Code API or using a mechanism outside of FusionAuth. The verification is completed by using the Verify Complete API with this code.
startverifyidentitywithid
StartWebAuthnLoginWithId
Start a WebAuthn authentication ceremony by generating a new challenge for the user
startwebauthnloginwithid
StartWebAuthnRegistrationWithId
Start a WebAuthn registration ceremony by generating a new challenge for the user
startwebauthnregistrationwithid
TwoFactorLoginWithId
Complete login using a 2FA challenge
twofactorloginwithid
UpdateApplicationRoleWithId
Updates the application role with the given Id for the application.
updateapplicationrolewithid
UpdateApplicationWithId
Updates the application with the given Id. OR Reactivates the application with the given Id.
updateapplicationwithid
UpdateConnectorWithId
Updates the connector with the given Id.
updateconnectorwithid
UpdateConsentWithId
Updates the consent with the given Id.
updateconsentwithid
UpdateEmailTemplateWithId
Updates the email template with the given Id.
updateemailtemplatewithid
UpdateEntityTypePermissionWithId
Updates the permission with the given Id for the entity type.
updateentitytypepermissionwithid
UpdateEntityTypeWithId
Updates the Entity Type with the given Id.
updateentitytypewithid
UpdateEntityWithId
Updates the Entity with the given Id.
updateentitywithid
UpdateFormFieldWithId
Updates the form field with the given Id.
updateformfieldwithid
UpdateFormWithId
Updates the form with the given Id.
updateformwithid
UpdateGroupMembersWithId
Creates a member in a group.
updategroupmemberswithid
UpdateGroupWithId
Updates the group with the given Id.
updategroupwithid
UpdateIdentityProviderWithId
Updates the identity provider with the given Id.
updateidentityproviderwithid
UpdateIntegrationsWithId
Updates the available integrations.
updateintegrationswithid
UpdateIPAccessControlListWithId
Updates the IP Access Control List with the given Id.
updateipaccesscontrollistwithid
UpdateKeyWithId
Updates the key with the given Id.
updatekeywithid
UpdateLambdaWithId
Updates the lambda with the given Id.
updatelambdawithid
UpdateMessageTemplateWithId
Updates the message template with the given Id.
updatemessagetemplatewithid
UpdateMessengerWithId
Updates the messenger with the given Id.
updatemessengerwithid
UpdateOAuthScopeWithId
Updates the OAuth scope with the given Id for the application.
updateoauthscopewithid
UpdateRegistrationWithId
Updates the registration for the user with the given Id and the application defined in the request.
updateregistrationwithid
UpdateSystemConfigurationWithId
Updates the system configuration.
updatesystemconfigurationwithid
UpdateTenantManagerConfigurationWithId
Updates the Tenant Manager configuration.
updatetenantmanagerconfigurationwithid
UpdateTenantManagerIdentityProviderTypeConfigurationWithId
Updates the tenant manager identity provider type configuration for the given identity provider type.
updatetenantmanageridentityprovidertypeconfigurationwithid
UpdateTenantWithId
Updates the tenant with the given Id.
updatetenantwithid
UpdateThemeWithId
Updates the theme with the given Id.
updatethemewithid
UpdateTwoFactorWithId
Updates the two-factor method for the given user using a JSON body.
updatetwofactorwithid
UpdateUserActionReasonWithId
Updates the user action reason with the given Id.
updateuseractionreasonwithid
UpdateUserActionWithId
Updates the user action with the given Id. OR Reactivates the user action with the given Id.
updateuseractionwithid
UpdateUserConsentWithId
Updates a single User consent by Id.
updateuserconsentwithid
UpdateUserFamilyWithId
Updates a family with a given Id. OR Adds a user to an existing family. The family Id must be specified.
updateuserfamilywithid
UpdateUserVerifyEmail
Re-sends the verification email to the user. If the Application has configured a specific email template this will be used instead of the tenant configuration. OR Re-sends the verification email to the user. OR Generate a new Email Verification Id to be used with the Verify Email API. This API will not attempt to send an email to the User. This API may be used to collect the verificationId for use with a third party system.
updateuserverifyemail
UpdateUserVerifyRegistration
Re-sends the application registration verification email to the user. OR Generate a new Application Registration Verification Id to be used with the Verify Registration API. This API will not attempt to send an email to the User. This API may be used to collect the verificationId for use with a third party system.
updateuserverifyregistration
UpdateUserWithId
Updates the user with the given Id. OR Reactivates the user with the given Id.
updateuserwithid
UpdateWebhookWithId
Updates the webhook with the given Id.
updatewebhookwithid
UpsertEntityGrantWithId
Creates or updates an Entity Grant. This is when a User/Entity is granted permissions to an Entity.
upsertentitygrantwithid
ValidateJWTWithId
Validates the provided JWT (encoded JWT string) to ensure the token is valid. A valid access token is properly signed and not expired. <p> This API may be used to verify the JWT as well as decode the encoded JWT into human readable identity claims.
validatejwtwithid
VendJWTWithId
It's a JWT vending machine! Issue a new access token (JWT) with the provided claims in the request. This JWT is not scoped to a tenant or user, it is a free form token that will contain what claims you provide. <p> The iat, exp and jti claims will be added by FusionAuth, all other claims must be provided by the caller. If a TTL is not provided in the request, the TTL will be retrieved from the default Tenant or the Tenant specified on the request either by way of the X-FusionAuth-TenantId request header, or a tenant scoped API key.
vendjwtwithid
VerifyIdentityWithId
Administratively verify a user identity.
verifyidentitywithid
VerifyUserRegistrationWithId
Confirms a user's registration. The request body will contain the verificationId. You may also be required to send a one-time use code based upon your configuration. When the application is configured to gate a user until their registration is verified, this procedures requires two values instead of one. The verificationId is a high entropy value and the one-time use code is a low entropy value that is easily entered in a user interactive form. The two values together are able to confirm a user's registration and mark the user's registration as verified.
verifyuserregistrationwithid
FAQ

FusionAuth integration, answered

How do AI agents use FusionAuth through Open Connector?
Your user connects FusionAuth once with one of its cataloged authentication methods. Open Connector stores the credential in an encrypted vault and exposes FusionAuth tools to your agent over MCP or a typed API, with credentials injected server-side on each call.
Is this a FusionAuth MCP server?
Yes. Open Connector can serve FusionAuth as a named MCP server with a scoped allowlist and a per-user connection URL, so any MCP client can call FusionAuth actions with credentials injected server-side.
Where do FusionAuth credentials live?
In your own infrastructure. Open Connector keeps credentials in its own vault and injects them at call time, so they never leave your environment.

Give your agents FusionAuth — keep the keys.

Open source, self-hostable, with FusionAuth credentials that never leave your infrastructure. Run it from source today.