Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Userfront API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fuserfront.com%2Fuserfront" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fuserfront.com%2Fuserfront" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Userfront API.
Create a user
List users
Get a user
Update a user
Delete a user
GET STARTED
Set user roles
Patterns agents use Userfront API for, with concrete tasks.
★ Identity and Authentication Operations
Use the Userfront API to perform identity auth operations programmatically. The API provides 14 endpoints covering core functionality including create a user, list users, get a user.
Call POST /v0/users to create a user
Automated Authentication Management
Automate authentication operations by combining multiple Userfront API endpoints. Agents can list users and then get a user in a single workflow.
Call GET /v0/users to list users, then verify the result
AI Agent Integration via Jentic
AI agents discover and call Userfront API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.
Search Jentic for 'create a user', load the operation schema, and execute with Jentic-managed credentials
14 endpoints — userfront is a user authentication and identity management platform.
METHOD
PATH
DESCRIPTION
/v0/users
Create a user
/v0/users
List users
/v0/users/{userId}
Get a user
/v0/users/{userId}
Update a user
/v0/users/{userId}
Delete a user
/v0/users/{userId}/roles
Get user roles
/v0/users/{userId}/roles
Set user roles
/v0/tenants/{tenantId}
Get tenant information
/v0/users
Create a user
/v0/users
List users
/v0/users/{userId}
Get a user
/v0/users/{userId}
Update a user
/v0/users/{userId}
Delete a user
/v0/users/{userId}/roles
Get user roles
/v0/users/{userId}/roles
Set user roles
/v0/tenants/{tenantId}
Get tenant information
What agents get from Jentic-routed access to this vendor.
Setup
Wiring the Userfront API by hand means attaching its bearer token and moving between user, role, and tenant endpoints yourself. Through Jentic you install once, import Userfront from the API Directory, store the token once, and your agent calls it.
Permission scoping
Userfront puts the user id in the URL path (/v0/users/{userId}), so a rule can pin your agent to one user: it can read that user and their roles if you allow it. You choose the operations it may call, so destructive ones like user deletion are not included unless you add them.
Credential isolation
Your Userfront token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'create a user' or 'read a user's roles', and Jentic returns the matching Userfront operation with its input schema so the agent calls the right endpoint without browsing the reference docs.
Alternatives and complements available in the Jentic catalogue.
Specific to using Userfront API through Jentic.
What authentication does the Userfront API use?
The Userfront API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.
Can I create a user with the Userfront API?
Yes. Use the POST /v0/users endpoint. The API returns structured JSON responses that agents can parse and act on directly.
What are the rate limits for the Userfront API?
Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.
How do I create a user through Jentic?
Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create a user'. Jentic returns the matching Userfront API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.
How many endpoints does the Userfront API have?
The Userfront API exposes 14 endpoints covering authentication, roles, tenants operations.
Can I limit what my agent is allowed to do with the Userfront API?
Yes. Jentic One is self-hosted by you, so your own rules decide which Userfront operations and credentials the agent may use. Because Userfront puts the user id in the URL path (/v0/users/{userId}), a rule can pin the agent to a single user, letting it read that user and their roles while blocking others. You choose the operations it may call, so destructive ones like DELETE /v0/users/{userId} are excluded unless you explicitly add them.
For Agents
Programmatically create a user, list users. Covers 14 operations with bearer authentication.
Use for: I need to a user, I want to users, Search for a user, Find all a user
Not supported: Does not handle payments, communications, or crm - use for identity and authentication only.
Userfront is a user authentication and identity management platform. The server-to-server API provides user management, tenant management, role management, and authentication token operations. The API exposes 14 endpoints secured with bearer authentication.
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>