canonical: https://jentic.com/apis/propelauth.com/propelauth

# PropelAuth API

PropelAuth is a B2B authentication service. The backend API provides endpoints for managing users, organizations, API keys, and access tokens. Supports user creation, fetching, updating, role management, organization management, and magic link generation. The API exposes 19 endpoints secured with bearer authentication.

## For AI agents

Programmatically fetch user by id, update user. Covers 19 operations with bearer authentication.

## Scope

Does not handle payments, communications, or crm - use for identity and authentication only.

## Capabilities

- Fetch user by ID
- Update user
- Delete user
- Create user
- Query users

## Use cases

### Identity and Authentication Operations

Use the PropelAuth API to perform identity auth operations programmatically. The API provides 19 endpoints covering core functionality including fetch user by id, update user, delete user.

Example prompt: Call GET `/api/backend/v1/user/{user_id}` to fetch user by id

### Automated Users Management

Automate users operations by combining multiple PropelAuth API endpoints. Agents can update user and then delete user in a single workflow.

Example prompt: Call PUT `/api/backend/v1/user/{user_id}` to update user, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call PropelAuth API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Example prompt: Search Jentic for 'fetch user by id', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/api/backend/v1/user/{user_id}` | Fetch user by ID |
| PUT | `/api/backend/v1/user/{user_id}` | Update user |
| DELETE | `/api/backend/v1/user/{user_id}` | Delete user |
| GET | `/api/backend/v1/user/email` | Fetch user by email |
| GET | `/api/backend/v1/user/username` | Fetch user by username |
| POST | `/api/backend/v1/user/` | Create user |
| GET | `/api/backend/v1/user/query` | Query users |
| POST | `/api/backend/v1/user/{user_id}/disable` | Disable a user |

## Key resources

- **Users** — User management
- **Organizations** — Organization management
- **Magic Links** — Magic link generation
- **API Keys** — API key management
- **Access Tokens** — Access token validation

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 62 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 74 / 100
  - Developer Experience & Jentic Compatibility: 63 / 100
  - AI-Readiness & Agent Experience: 45 / 100
  - Agent Usability: 94 / 100
  - Security: 60 / 100
  - AI Discoverability: 66 / 100
- **View full report:** https://jentic.com/apis/propelauth.com/propelauth/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring the PropelAuth API by hand means setting bearer auth, pointing requests at your own auth_url host, and managing user records yourself. Through Jentic you install once, import PropelAuth from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** PropelAuth puts the user id in the URL path (`/api/backend/v1/user/{user_id}`), so a rule can pin your agent to acting on one user. You choose the operations it may call, so destructive ones like deleting or disabling a user are not included unless you add them.
- **Credential handling:** Your PropelAuth API token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'fetch a user by id' or 'look up a user by email', and Jentic returns the matching PropelAuth operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Auth0** — Alternative identity auth API
- **Okta** — Alternative identity auth API

## FAQ

### What authentication does the PropelAuth API use?

The PropelAuth API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I fetch user by id with the PropelAuth API?

Yes. Use the GET `/api/backend/v1/user/{user_id}` endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the PropelAuth API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I fetch user by id through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'fetch user by id'. Jentic returns the matching PropelAuth API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the PropelAuth API have?

The PropelAuth API exposes 19 endpoints covering users, organizations, magic links operations.

### Can I limit what my agent is allowed to do with the PropelAuth API?

Yes. Because you run Jentic One yourself, your own rules decide which PropelAuth operations and credentials the agent may use, so you can grant read calls like GET `/api/backend/v1/user/{user_id}` while withholding destructive ones such as deleting or disabling a user. PropelAuth also carries the user id in the URL path (`/api/backend/v1/user/{user_id}`), so a rule can pin the agent to acting on a single user rather than the whole directory. Nothing is callable unless you have added it to the operation set.
