Skip to main content
Authenticate callers and manage account and project access. Assign access through account and project roles. Private resources may require additional permissions. Authentication · Current user · Accounts · Account Collaboration · Account Members · Account Invitations · Account directory · Project Members · Project Invitations · Project Ownership · API keys · OAuth Metadata · OAuth Clients · OAuth Authorization Requests · OAuth Tokens · OAuth Grants

Authentication

Sign in through an identity provider or magic link, create tokens, and end sessions. Retrieve public verification keys from the JWKS endpoint.

Current user

Read the authenticated user’s profile.

Accounts

List, create, or read accounts.

Account Collaboration

Read owner-wide collaboration entitlements and seat usage. The project reference selects its owner.

Account Members

List, update, or remove account members.

Account Invitations

List, create, revoke, or accept account invitations.

Account directory

List pending invitations and active members across projects you own.

Project Members

List, read, remove, or update project members.

Project Invitations

Create, read, delete, or resend project invitations.

Project Ownership

Transfer project ownership.

API keys

Create, inspect, update, and revoke API keys. View API key usage in the Billing and Usage API.

OAuth Metadata

Discover OAuth authorization and protected-resource metadata.

OAuth Clients

Register public OAuth clients.

OAuth Authorization Requests

Start, read, or decide MCP authorization requests.

OAuth Tokens

Exchange, rotate, or revoke OAuth tokens.

OAuth Grants

List or revoke authorized MCP app grants. Back to REST API reference