Passura API

Passura is EU-native authentication. This is the developer documentation for its HTTP API — the same API the Passura Console is built on. Everything is REST over JSON; there is no SDK to install.

Base URL

All examples use https://api.passura.dev. In local development the API runs at http://localhost:3000.

Multi-tenant by design

Every account is a tenant, addressed by a URL-safe slug. Almost every route is scoped to a tenant:

/v1/{tenantSlug}/...

A single tenant is created when you sign up, and the sessions and API keys you issue belong to that tenant. A credential minted for one tenant is rejected on another — tenant isolation is enforced at the auth layer, not just in your queries.

What you can do today

  • Sign in — email and password (hashed with Argon2id), and Google sign-in.
  • MFA — TOTP authenticator apps and email one-time codes, per-tenant policy.
  • Sessions — short-lived JWT access tokens with rotating refresh tokens and family-based reuse detection.
  • API keys — scoped live and test keys for server-to-server calls.
  • Audit log — every auth event, recorded and queryable.
  • Agent identity — drive scoped operations over MCP.
  • GDPR — data export and right-to-erasure, built in.

Authenticating requests

Requests carry a bearer credential in the Authorization header — either a user access token or an API key:

curl https://api.passura.dev/v1/acme/me \
  -H "Authorization: Bearer <access-token-or-api-key>"

Which one you use depends on the caller: a signed-in user acts with an access token; a backend service acts with an API key. See Authentication & sessions for the full model.

Next steps