Passura API
Passura is EU-native authentication. This is the developer documentation for its HTTP API — the same API the Passura Console is built on. Everything is REST over JSON; there is no SDK to install.
All examples use https://api.passura.dev. In local development the API runs at
http://localhost:3000.
Multi-tenant by design
Every account is a tenant, addressed by a URL-safe slug. Almost every route is scoped to a tenant:
/v1/{tenantSlug}/...
A single tenant is created when you sign up, and the sessions and API keys you issue belong to that tenant. A credential minted for one tenant is rejected on another — tenant isolation is enforced at the auth layer, not just in your queries.
What you can do today
- Sign in — email and password (hashed with Argon2id), and Google sign-in.
- MFA — TOTP authenticator apps and email one-time codes, per-tenant policy.
- Sessions — short-lived JWT access tokens with rotating refresh tokens and family-based reuse detection.
- API keys — scoped
liveandtestkeys for server-to-server calls. - Audit log — every auth event, recorded and queryable.
- Agent identity — drive scoped operations over MCP.
- GDPR — data export and right-to-erasure, built in.
Authenticating requests
Requests carry a bearer credential in the Authorization header — either a user
access token or an API key:
curl https://api.passura.dev/v1/acme/me \
-H "Authorization: Bearer <access-token-or-api-key>"
Which one you use depends on the caller: a signed-in user acts with an access token; a backend service acts with an API key. See Authentication & sessions for the full model.
Next steps
- Quickstart — from zero to a first authenticated request.
- Authentication & sessions — tokens, refresh, and rotation.
- API reference — every endpoint, generated from the OpenAPI spec.