canonical: https://jentic.com/apis/swaggerhub.favor-ex/barong

# Favor Ex Barong

RESTful API for barong OAuth server. The API exposes 78 endpoints secured with jwt authentication.

## For AI agents

Programmatically getadminlevels, getadminprofiles. Covers 78 operations with jwt authentication.

## Scope

Does not handle payments, communications, or crm - use for identity and authentication only.

## Capabilities

- getAdminLevels
- getAdminProfiles
- putAdminProfiles
- deleteAdminProfiles
- postAdminRestrictions
- getAdminRestrictions
- putAdminRestrictions

## Use cases

### Identity and Authentication Operations

Use the Barong to perform identity auth operations programmatically. The API provides 78 endpoints covering core functionality including getadminlevels, getadminprofiles, putadminprofiles.

Example prompt: Call GET `/admin/levels` to getadminlevels

### Automated admin Management

Automate admin operations by combining multiple Barong endpoints. Agents can getadminprofiles and then putadminprofiles in a single workflow.

Example prompt: Call GET `/admin/profiles` to getadminprofiles, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Barong endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle jwt tokens manually.

Example prompt: Search Jentic for 'getadminlevels', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/admin/levels` | getAdminLevels |
| GET | `/admin/profiles` | getAdminProfiles |
| PUT | `/admin/profiles` | putAdminProfiles |
| DELETE | `/admin/profiles` | deleteAdminProfiles |
| POST | `/admin/restrictions` | postAdminRestrictions |
| GET | `/admin/restrictions` | getAdminRestrictions |
| PUT | `/admin/restrictions` | putAdminRestrictions |
| DELETE | `/admin/restrictions` | deleteAdminRestrictions |

## Key resources

- **admin** — Operations about admins
- **identity** — Operations about identities
- **resource** — Operations about resources

## Why Jentic

- **Setup:** Wiring Barong by hand means handling its JWT bearer auth, passing the token in the Authorization header on every call, and refreshing it yourself across its admin and account operations. Through Jentic you install once, import Barong from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** Barong admin routes carry their target in the request body rather than the path, so scope the agent to the operations it needs, such as reading admin levels or profiles. You choose the operations it may call, so state-changing ones like updating or deleting profiles and restrictions are not included unless you add them.
- **Credential handling:** Your Barong JWT is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'list identity verification levels' or 'review a member profile', and Jentic returns the matching Barong operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Auth0** — Alternative identity auth API
- **Okta** — Alternative identity auth API

## FAQ

### What authentication does the Barong use?

The Barong uses jwt authentication. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I getadminlevels with the Barong?

Yes. Use the GET `/admin/levels` endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Barong?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I getadminlevels through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'getadminlevels'. Jentic returns the matching Barong operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Barong have?

The Barong exposes 78 endpoints covering admin, identity, resource operations.

### Can I limit what my agent is allowed to do with the Barong API?

Yes. Because you self-host Jentic One, your own rules decide which Barong operations and credentials your agent may use. You can allow read-only calls like getting admin levels or reading admin profiles while withholding state-changing ones such as updating or deleting profiles and restrictions, which stay out of reach unless you add them. Note that Barong admin routes carry their target in the request body rather than the path, so scoping is done per operation rather than by URL pattern.
