Management API Specification
Servers
List the vendors the user can access
Get vendors from organization memberships or global admin:organizations / access:all_organizations grants on the Authhero Management API. Discovery does not grant provisioning rights.
Authorizations
Responses
The vendors the user can access
POST /management/vendors
Get a vendor the user can access
Get one vendor, including its business currency. Allowed by organization membership or global admin:organizations / access:all_organizations grants on the Authhero Management API, the same rule as the vendor list.
Authorizations
Parameters
Path Parameters
"acme"Responses
The vendor
GET /management/bills
Authorizations
Parameters
Query Parameters
"DRAFT""PENDING""PAID""RETRYING""OVERDUE""CANCELED""EXPIRED""DELETED""VOIDED""2026-01-01T00:00:00Z""date-time""(?:Z|[+-]\\d{2}:\\d{2})$""2026-01-31T23:59:59Z""date-time""(?:Z|[+-]\\d{2}:\\d{2})$""2026-01-01T00:00:00Z""date-time""(?:Z|[+-]\\d{2}:\\d{2})$""2026-01-31T23:59:59Z""date-time""(?:Z|[+-]\\d{2}:\\d{2})$"Responses
Retrieve the users bills
GET /management/bills/{id}
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Responses
Retrieve the users bills
Contracts
Operations
GET /management/contracts
Authorizations
Parameters
Query Parameters
Responses
Retrieve the users contracts
Create a contract
Creates a contract for a user without a checkout, billed by invoice. The contract is returned as PENDING: priced, but not billed and granting no access. Review it, then confirm it with POST /management/contracts/{id}/confirm, or pass confirm: true to do both in one call. For a multi-seat contract, use a license product; quantity is what is billed and seats optionally sets how many seats that buys. Creating is not idempotent: a repeated request creates a second contract.
Authorizations
Request Body
Responses
The created contract
GET /management/contracts/{id}
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Responses
Retrieve the users contracts
Confirm a contract
Confirms a PENDING contract: the customer is billed and access is granted, including the seats of a multi-seat contract. A contract that starts later becomes FORTHCOMING instead of ACTIVE. Confirming an already confirmed contract returns it unchanged.
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Responses
The confirmed contract
Set the seats of a contract
Sets how many seats a multi-seat contract grants. It does not change what is billed: the seats are not part of the price. The change applies at once. Setting the seats the contract already has returns it unchanged. Seats cannot be lowered below the number of users holding one.
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Request Body
Responses
The contract with its new seats
List users holding contract seats
Lists the users holding seats across all license items on a multi-seat contract. Removed seats are left out. Filter by sku to list one item.
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Query Parameters
Responses
Users holding seats on the contract
Assign a contract seat to a user
Assigns a seat by email. Vault picks the license item with a free seat. The change does not affect billing.
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Request Body
Responses
Seat assigned
Remove a user from a contract seat
Removes a user from the contract seat license. The change does not affect billing.
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353""auth0|123456"Responses
Seat user removed
List users holding contract seats (deprecated)
Use GET /management/contracts/{id}/seats/users instead.
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Responses
Retrieve users with license entitlements for the contract
List upgrade options
Lists the products and purchase options each item of the contract can be upgraded, downgraded, or switched to. Returns 400 when the contract cannot be changed (inactive or non-recurring).
Authorizations
Parameters
Path Parameters
"1d78271264b9c76d5842911dd70b4353"Responses
The available upgrade and downgrade paths for the contract
GET /management/transactions
Authorizations
Parameters
Query Parameters
Responses
A list of transactions
GET /management/products
Authorizations
Parameters
Query Parameters
Responses
Retrieve a list of products
POST /management/products
Authorizations
Request Body
Responses
A created product
GET /management/products/{sku}
Authorizations
Parameters
Path Parameters
Responses
Retrieve a a product by SKU
PATCH /management/products/{sku}
Authorizations
Parameters
Path Parameters
Request Body
Responses
The updated product
GET /management/products/{sku}/fulfillments
Authorizations
Parameters
Path Parameters
Responses
Retrieve a a product by SKU
Users
Operations
List user logs
Returns paginated user logs for the authenticated vendor.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Query Parameters
00110020Responses
User logs and total matching count
List user sessions
Returns paginated user sessions for the authenticated vendor.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Query Parameters
00110020Responses
User sessions and total matching count
List users
Returns a list of users with optional filtering.
Authorizations
Parameters
Query Parameters
"john""10""0"Responses
A list of users matching the query parameters
Create a user
Creates a new user with the specified email and optional name.
Authorizations
Request Body
Responses
User created successfully
Get a user by ID
Retrieves a specific user's profile by their ID.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Responses
The requested user profile
Delete a user
Deletes a user from the auth server. This action is irreversible. Set allowPurchases=true to allow one-off purchase entitlements. Active subscription entitlements and active, overdue or forthcoming contracts always block deletion.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Query Parameters
"true""false""false""false"Responses
User deleted successfully
Update a user
Updates a specific user's profile with the provided data.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Request Body
Responses
The updated user profile
Change user login identifier
Changes the email address that a user uses to log in.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Request Body
Responses
Login identifier changed successfully
Add phone login identifier
Creates a new SMS user in Auth0 and links it as an additional login identity to the existing user.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Request Body
Responses
Phone identifier added successfully
Set user metadata value
Sets a metadata value for a specific user with the specified key.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"The key of the metadata entry
"preferences"Request Body
Responses
Metadata value set successfully
Delete user metadata value
Deletes a metadata value for a specific user with the specified key.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"The key of the metadata entry
"preferences"Responses
Metadata value deleted successfully
Set user password
Sets or updates the password for a user. Creates a password authentication method if one does not exist.
Authorizations
Parameters
Path Parameters
The unique identifier of the user
"user123"Request Body
Responses
Password set successfully
List team members
Returns the list of users with portal access for the current vendor.
Authorizations
Responses
A list of team members
Invite a team member
Adds a new team member identified by email and assigns one or more portal roles.
Authorizations
Request Body
Responses
Team member added successfully
Set team member roles
Replaces the portal roles for a team member. Only portal-managed roles are affected; other roles on the user are left untouched. Pass an empty array to remove all portal roles.
Authorizations
Parameters
Path Parameters
"auth0|61715b8ebe82f0006ab0613b"Request Body
Responses
Roles updated successfully
Remove a team member
Removes all portal-managed role assignments for a user. Other roles on the user are left untouched.
Authorizations
Parameters
Path Parameters
"auth0|61715b8ebe82f0006ab0613b"Responses
Team member removed
List API keys
Returns the vendor's machine-to-machine API keys, newest first. Secrets are never included — a secret is readable only in the response that created it.
Authorizations
Responses
The vendor's API keys
Create an API key
Creates a machine-to-machine key and returns its secret. This is the only response that ever carries the secret. Use the returned clientId, clientSecret, tokenUrl and audience in an OAuth 2.0 client-credentials exchange to mint Management API tokens.
Authorizations
Request Body
Responses
Key created — the secret is in this response and nowhere else
Revoke an API key
Revokes the key immediately and irreversibly. Tokens already minted with it keep working until they expire — the key can mint no new ones. Only API keys can be deleted here; a client id belonging to a site is reported as not found.
Authorizations
Parameters
Path Parameters
"apikey_9f2c1d8e4b7a4f1e9c3d5a6b7c8d9e0f"Responses
Key revoked
Get customer information
Returns customer information in XML format for Mediaconnect compatibility.
Authorizations
Parameters
Path Parameters
The unique identifier of the customer
"958280"Responses
Customer information in XML format
GET /management/entitlements
Authorizations
Parameters
Query Parameters
"premium article""20""cursor123""user123""article""audiobook""ebook""bundle""podcast""pass""publication""physical_issue""article""premium-article-123"Responses
List of entitlements
Get a checkout by id
Fetches a single checkout belonging to the caller's vendor. Primarily used to hydrate a checkout.1#confirm webhook event, which carries only a checkoutId.
Authorizations
Parameters
Path Parameters
The unique identifier of the checkout
"checkout123"Responses
The checkout
Discounts
Operations
List discounts
Authorizations
Parameters
Query Parameters
"DRAFT""PENDING""ACTIVE""PAUSED""EXPIRED""CANCELED""ACTIVATION_ERROR""percentage""fixedAmount""trialPeriod""specialPriceTranche""developerTest"501100Responses
The discounts
Create a discount
Creates a discount as a DRAFT. It applies to nothing until it is activated with POST /management/discounts/{id}/activate. parameters and conditions depend on type. Creating is not idempotent: a repeated request creates a second discount.
Authorizations
Request Body
Responses
The created discount
Get a discount
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Responses
The discount
Update a discount
Changes the fields sent and leaves the rest. parameters and conditions are replaced whole when sent. Only DRAFT and PAUSED discounts can be edited: pause an active discount first. The type cannot be changed.
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Request Body
Responses
The updated discount
Activate a discount
Schedules a DRAFT or PAUSED discount. It becomes PENDING, and ACTIVE once its start date is reached. Activating an already PENDING or ACTIVE discount returns it unchanged.
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Responses
The discount with its new status
Pause a discount
Stops a PENDING or ACTIVE discount from applying to new purchases until it is activated again. A paused discount can be edited. Subscriptions that already have it keep it.
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Responses
The discount with its new status
Cancel a discount
Retires a DRAFT or PAUSED discount for good. Pause an active discount first. Subscriptions that already have it keep it.
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Responses
The discount with its new status
List one-time codes
Lists the single-use codes generated for a discount.
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Query Parameters
501100Responses
The codes
Generate one-time codes
Generates single-use codes that each apply the discount once. Not idempotent: a repeated request generates another batch.
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Request Body
Responses
The generated codes
Cancel one-time codes
Cancels every code of the discount that has not been redeemed. Redeemed codes are kept.
Authorizations
Parameters
Path Parameters
"6f1c1f0e-2b8e-4f8a-9d9c-2f7c1b1e0a11"Responses
The unredeemed codes were canceled
List paywalls
Lists all paywalls configured for the authenticated vendor.
Authorizations
Responses
The list of paywalls for the vendor
Get paywall by ID
Retrieves the paywall configuration and settings for the specified paywall ID. This resolves the rendered paywall, so — unlike the list route — the response does not carry the admin-only name, status, entity, createdAt, modifiedAt or previewUrl fields.
Authorizations
Parameters
Path Parameters
"pw123456"Responses
The paywall information and configuration
GET /management/access-lists
Authorizations
Responses
Retrieve a list of access lists
POST /management/access-lists
Authorizations
Request Body
Responses
Access list created successfully
GET /management/access-lists/{id}
Authorizations
Parameters
Path Parameters
"src_123abc"Responses
Retrieve an access list by ID
PUT /management/access-lists/{id}
Authorizations
Parameters
Path Parameters
"src_123abc"Request Body
Responses
Access list updated successfully
PATCH /management/access-lists/{id}
Authorizations
Parameters
Path Parameters
"src_123abc"Request Body
Responses
Access list patched successfully
GET /management/access-lists/{id}/grants
Authorizations
Parameters
Path Parameters
"src_123abc"Responses
Retrieve a list of grants for an access list
POST /management/access-lists/{id}/grants
Authorizations
Parameters
Path Parameters
"src_123abc"Request Body
Responses
Grant created successfully
GET /management/access-lists/{id}/grants/{grantId}
Authorizations
Parameters
Path Parameters
"src_123abc""purchase_123abc"Responses
Retrieve a grant by ID
PUT /management/access-lists/{id}/grants/{grantId}
Authorizations
Parameters
Path Parameters
"src_123abc""purchase_123abc"Request Body
Responses
Grant updated successfully
DELETE /management/access-lists/{id}/grants/{grantId}
Authorizations
Parameters
Path Parameters
"src_123abc""purchase_123abc"Responses
Grant deleted successfully
List all sites for the calling vendor
Returns every site with per-capability status. Each upstream is read once per vendor, so a vendor with 200 sites costs the same round-trips as one with a single site. A failing upstream degrades only its own capability to failed rather than failing the whole response.
Authorizations
Responses
All sites registered under this vendor
Get a single site
Authorizations
Parameters
Path Parameters
"alingsasnytt.se"Responses
The site, with resolved content selectors and capsule config
Provision or update a site
Every block is optional and provisioning is strictly opt-in per capability — omitted blocks are left untouched. Legs run least-live-first (client → content → login domain → scrape origin) and each is attempted independently, so one failure does not abandon the rest. Returns 207 when some legs succeeded and others failed; retry should target only the failed ones.
Authorizations
Parameters
Path Parameters
"alingsasnytt.se"Request Body
Responses
All requested capabilities provisioned
Delete a site
Removes the site from every upstream it was provisioned into. Destructive and not reversible: the AuthHero client is deleted, so re-provisioning mints a new client_id and every end-user session and the installed snippet break with it. Prefer PUT with scraper.active: false to take a domain out of service. Legs run most-live-first (scrape origin -> capsule -> login domain -> content config -> client) and each is attempted independently, so a teardown that stops halfway leaves the site inert rather than scraped with a dead client. Only legs with something to remove are reported. The request carries no body, so a retry re-runs every applicable leg rather than a chosen subset; legs whose upstream resource is already absent report ok, so a retry after a partial teardown converges. Returns 207 when some legs failed and 502 when all did.
Authorizations
Parameters
Path Parameters
"alingsasnytt.se"Responses
Every leg torn down
Get user diagnostics
Retrieve diagnostics entries for a user by their user ID or fallback ID. Returns the most recent entries.
Authorizations
Parameters
Path Parameters
"user_123"Query Parameters
"10"Responses
List of diagnostics entries
Delete user diagnostics
Delete all diagnostics entries for a user by their user ID or fallback ID.
Authorizations
Parameters
Path Parameters
"user_123"Responses
Diagnostics deleted successfully
Get a metric over time
Returns one metric for the vendor across a date range: a headline figure plus a per-product daily series. Monetary values are in major units (e.g. kronor) with the currency named in currency.
Authorizations
Parameters
Path Parameters
"currentMrr""newMrr""churnMrr""projectedMrr""totalRevenue""totalSales""subscriptionSales""totalSubscribers""currentMrr"Query Parameters
"2026-01-01""date""2026-03-31""date"Responses
The metric over the requested range
Get purchases attributed to a tracking dimension
Returns a checkout-attribution table for the vendor, grouped by one tracking dimension (UTM tags, referrer, or the content the visit came from). Each row carries sessions, users, transactions, conversion rate and revenue per currency. Rows whose purchases carried no value for the dimension have a null key.
Authorizations
Parameters
Path Parameters
"utm_source""utm_medium""utm_campaign""utm_content""utm_source_medium""referrer""item_source""section""tag""author""utm_source"Query Parameters
"2026-01-01""date""2026-03-31""date""all""subscriptions""single""all""all"1000true1000100Responses
The attribution breakdown for the requested range
List the available metrics and dimensions
Returns every metric /series/{metric} accepts and every dimension /breakdown/{dimension} accepts, with a title and description for each. Static — it makes no upstream call — so a client can discover the surface instead of hard-coding it.
Authorizations
Responses
The metrics and dimensions this API exposes
Create a signed link for content access
Creates a signed token that grants access to encrypted content. Optionally appends it to a URL. Use for share links, email campaigns, gift access, or temporary tier access.
Authorizations
Request Body
Responses
The signed link/token
List trusted publisher domains for the calling vendor
Authorizations
Responses
All trusted publisher domains registered under this vendor
Get a single trusted publisher domain
Authorizations
Parameters
Path Parameters
Publisher domain (lowercase, no scheme, no trailing dot)
"example.wordpress.com"Responses
The trusted publisher domain entry
Register or update a trusted publisher domain
Upserts a trusted publisher domain entry under the calling vendor. Provide exactly one of signingKeyPem (pinned ES256) or jwksUri (HTTPS URL whose hostname matches {domain}). Idempotent: re-registration replaces the entry and advances updatedAt.
Authorizations
Parameters
Path Parameters
Publisher domain (lowercase, no scheme, no trailing dot)
"example.wordpress.com"Request Body
Responses
Domain updated
Remove a trusted publisher domain
Authorizations
Parameters
Path Parameters
Publisher domain (lowercase, no scheme, no trailing dot)
"example.wordpress.com"Responses
Domain removed (or did not exist)