Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
WorkOS website screenshot

WorkOS

WorkOS is the "Enterprise Ready" identity platform for B2B SaaS — providing AuthKit user management, enterprise SSO (SAML/OIDC), Directory Sync (SCIM 2.0), Multi-Factor Authentication, Audit Logs, Admin Portal, Fine-Grained Authorization (FGA, formerly Warrant), Radar bot/fraud protection, and an emerging suite of agent-oriented surfaces (Pipes, MCP Auth, auth.md).

agent native

Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.

Kin Score

API Evangelist profiles WorkOS the way a machine reads it — 265 machine-readable artifacts across 41 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — WorkOS scores 68.5/100 (strong), with a separate agent-readiness read of 71/100 (agent native). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 68.5/100 · strong
Contract Quality 16.6 / 25
Developer Ergonomics 11.7 / 20
Commercial Clarity 11.6 / 20
Operational Transparency 8.9 / 13
Governance 10.4 / 12
Discoverability 9.3 / 10
Agent readiness — 71/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile WorkOS

Each block below is one kind of artifact we hold for WorkOS. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 41

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

WorkOS admin-portal API

Endpoints for the Admin Portal API.

WorkOS api_keys API

Manage API keys for environments.

WorkOS application.client-secrets API

Manage client secrets for Connect Applications.

WorkOS applications API

Manage Connect Applications.

WorkOS audit-logs API

Create and query audit log events.

WorkOS authorization API

Authorization and access control.

WorkOS connections API

Manage SSO connections.

WorkOS directories API

Manage directories.

WorkOS directory-groups API

Manage directory groups.

WorkOS directory-users API

Manage directory users.

WorkOS events API

Query events and event streams.

WorkOS feature-flags API

Manage feature flags.

WorkOS feature-flags.targets API

Manage feature flag targets.

WorkOS groups API

Organize and manage user groups within organizations.

WorkOS multi-factor-auth API

Multi-factor authentication factor management.

WorkOS multi-factor-auth.challenges API

Multi-factor authentication challenge verification.

WorkOS organization-domains API

Manage organization domains.

WorkOS organizations.api_keys API

Manage organization-scoped API keys.

WorkOS organizations API

Manage organizations.

WorkOS organizations.feature-flags API

Manage organization-scoped feature flags.

WorkOS permissions API

Manage permissions.

WorkOS pipes API

Data integration endpoints.

WorkOS radar API

Radar fraud detection.

WorkOS sso API

Single Sign-On endpoints.

WorkOS user-management.authentication API

User authentication endpoints.

WorkOS user-management.cors-origins API

Manage CORS origins for user management.

WorkOS user-management.invitations API

Manage user invitations.

WorkOS user-management.multi-factor-authentication API

Multi-factor authentication endpoints.

WorkOS user-management.organization-membership API

Manage user organization memberships.

WorkOS user-management.organization-membership.groups API

Manage groups for a user organization membership.

WorkOS user-management.session-tokens API

Session token verification keys.

WorkOS user-management.users.authorized-applications API

Manage authorized applications for users.

WorkOS user-management.users.feature-flags API

Manage user-scoped feature flags.

WorkOS webhooks API

Manage webhooks.

WorkOS widgets API

Widget endpoints.

WorkOS workos-connect API

A unified interface that simplifies authentication and authorization across customers, partners, and external SaaS tools.

Scroll within the panel for all 41 ·

Open Collections 1

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

WorkOS

OPEN COLLECTION

MCP Servers 1

Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.

Model Context Protocol servers that expose these APIs to AI agents.

Pipes MCP Server

MCP SERVER

Agent Skills 2

An agent skill packages the how-to for driving these APIs from an assistant — the prompts, the sequence, the guardrails — so the knowledge to use the API travels with it.

Packaged agent skills for driving this provider's APIs from an AI assistant.

workos-widgets

AGENT SKILL

workos

AGENT SKILL

GraphQL 1

Where a provider ships GraphQL, the schema is the contract. We profile it alongside the REST surface so the whole interface is legible in one place.

GraphQL schemas published by this provider.

WorkOS GraphQL Schema

WorkOS exposes a **REST-only** public API (`https://api.workos.com`). This directory contains a **conceptual GraphQL schema** (`workos-schema.graphql`) derived from WorkOS's pub...

GRAPHQL

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Workos Plans Pricing

7 plans

PLANS

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Workos Rate Limits

4 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Features 21

The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.

Notable capabilities this provider offers.

Tagline: "Your app, Enterprise Ready."
AuthKit: free up to 1M MAU, then $2,500/mo per additional 1M
Single Sign-On: tiered $50-$125 per active SAML/OIDC connection (1-200+ tiers)
Directory Sync (SCIM): tiered $50-$125 per connection mirroring SSO
Audit Logs: $125/mo per SIEM destination + $99/mo per 1M events retained
Radar: 1,000 checks free, then $100/mo per 50K checks
Custom Domain: $99/mo
Scale Support: $1,000/mo; Enterprise custom
REST base URL: https://api.workos.com (staging: api.workos-test.com)
Default rate limit: 600 req/min; auth 60 req/min; Directory Sync 10/sec
50+ identity provider integrations (Okta, Entra, Google Workspace, JumpCloud, OneLogin, PingFederate, etc.)
SCIM 2.0 directory providers: Azure SCIM, Okta SCIM, BambooHR, Workday, HiBob, Rippling, JumpCloud, OneLogin, PingFederate, S/FTP, generic SCIM 2.0
Bearer token auth (sk_test_*/sk_live_*); supports organization-scoped and user-scoped API keys
Sealed sessions, magic auth, passkeys, social, password, enterprise SSO
FGA (formerly Warrant): relationship-based authorization, custom roles, edge agent
Audit Logs stream to Splunk, Datadog, Elastic and other SIEMs
MCP Auth + Resource Indicators (RFC 8707) for per-server scoping
Pipes: human-approved, provider-scoped credentials for AI agents
auth.md open protocol: agents register for services via Markdown at a domain
Self-service Admin Portal (white-label) for IT admins
SOC 2 Type 2, GDPR, HIPAA-eligible

Scroll within the panel for all 21 ·

Semantic Vocabularies 1

JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.

JSON-LD contexts and semantic vocabularies used across these APIs.

Workos Context

18 classes · 5 properties

JSON-LD

Spectral Rules 2

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

WorkOS API Rules

5 rules · 4 warnings

SPECTRAL

WorkOS API Rules

13 rules · 4 errors · 6 warnings

SPECTRAL

JSON Schema 162

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

AddRolePermissionDto

1 properties

JSON SCHEMA

ApiKey

9 properties

JSON SCHEMA

ApiKeyValidationResponse

1 properties

JSON SCHEMA

AssignRoleDto

0 properties

JSON SCHEMA

WorkOS Audit Log Event

9 properties

JSON SCHEMA

AuditLogActionJson

5 properties

JSON SCHEMA

AuditLogConfiguration

4 properties

JSON SCHEMA

AuditLogEventActorDto

4 properties

JSON SCHEMA

AuditLogEventContextDto

2 properties

JSON SCHEMA

AuditLogEventCreateResponse

1 properties

JSON SCHEMA

AuditLogEventDto

7 properties

JSON SCHEMA

AuditLogEventIngestionDto

2 properties

JSON SCHEMA

AuditLogEventTargetDto

4 properties

JSON SCHEMA

AuditLogExportCreationDto

8 properties

JSON SCHEMA

AuditLogExportJson

6 properties

JSON SCHEMA

AuditLogSchemaActorDto

1 properties

JSON SCHEMA

AuditLogSchemaDto

3 properties

JSON SCHEMA

AuditLogSchemaJson

6 properties

JSON SCHEMA

AuditLogSchemaTargetDto

2 properties

JSON SCHEMA

AuditLogsRetentionJson

1 properties

JSON SCHEMA

AuthenticationChallenge

7 properties

JSON SCHEMA

AuthenticationChallengeVerifyResponse

2 properties

JSON SCHEMA

AuthenticationFactor

8 properties

JSON SCHEMA

AuthenticationFactorEnrolled

8 properties

JSON SCHEMA

AuthorizationCheck

1 properties

JSON SCHEMA

AuthorizationPermission

9 properties

JSON SCHEMA

AuthorizationPermissionList

3 properties

JSON SCHEMA

AuthorizationResource

10 properties

JSON SCHEMA

AuthorizationResourceList

3 properties

JSON SCHEMA

AuthorizedConnectApplicationList

3 properties

JSON SCHEMA

ChallengeAuthenticationFactorDto

1 properties

JSON SCHEMA

CheckAuthorizationDto

0 properties

JSON SCHEMA

ConfirmEmailChangeDto

1 properties

JSON SCHEMA

ConnectApplication

0 properties

JSON SCHEMA

ConnectApplicationList

3 properties

JSON SCHEMA

ConnectedAccount

8 properties

JSON SCHEMA

WorkOS SSO Connection

10 properties

JSON SCHEMA

ConnectionList

3 properties

JSON SCHEMA

CorsOriginResponse

5 properties

JSON SCHEMA

CreateApplicationSecretDto

0 properties

JSON SCHEMA

CreateAuthorizationPermissionDto

4 properties

JSON SCHEMA

CreateAuthorizationResourceDto

0 properties

JSON SCHEMA

CreateCorsOriginDto

1 properties

JSON SCHEMA

CreateGroupDto

2 properties

JSON SCHEMA

CreateGroupMembershipDto

1 properties

JSON SCHEMA

CreateM2MApplicationDto

5 properties

JSON SCHEMA

CreateOAuthApplicationDto

8 properties

JSON SCHEMA

CreateOrganizationApiKeyDto

2 properties

JSON SCHEMA

CreateOrganizationDomainDto

2 properties

JSON SCHEMA

CreateOrganizationRoleDto

4 properties

JSON SCHEMA

CreatePasswordResetDto

2 properties

JSON SCHEMA

CreatePasswordResetTokenDto

1 properties

JSON SCHEMA

CreateRedirectUriDto

1 properties

JSON SCHEMA

CreateRoleDto

4 properties

JSON SCHEMA

CreateUserApiKeyDto

3 properties

JSON SCHEMA

CreateUserlandMagicCodeAndReturnDto

2 properties

JSON SCHEMA

CreateUserlandUserDto

0 properties

JSON SCHEMA

CreateUserlandUserInviteOptionsDto

6 properties

JSON SCHEMA

CreateWebhookEndpointDto

2 properties

JSON SCHEMA

DataIntegrationAccessTokenResponse

0 properties

JSON SCHEMA

DataIntegrationAuthorizeUrlResponse

1 properties

JSON SCHEMA

DataIntegrationsListResponse

2 properties

JSON SCHEMA

DeviceAuthorizationResponse

6 properties

JSON SCHEMA

WorkOS Directory

9 properties

JSON SCHEMA

DirectoryGroup

9 properties

JSON SCHEMA

DirectoryGroupList

3 properties

JSON SCHEMA

DirectoryList

3 properties

JSON SCHEMA

DirectoryUser

19 properties

JSON SCHEMA

DirectoryUserList

3 properties

JSON SCHEMA

DirectoryUserWithGroups

20 properties

JSON SCHEMA

DomainVerificationIntentOptions

1 properties

JSON SCHEMA

EmailChange

5 properties

JSON SCHEMA

EmailVerification

8 properties

JSON SCHEMA

EventContextActorDto

3 properties

JSON SCHEMA

EventContextDto

6 properties

JSON SCHEMA

EventList

3 properties

JSON SCHEMA

EventSchema

0 properties

JSON SCHEMA

ExternalAuthCompleteResponse

1 properties

JSON SCHEMA

WorkOS FGA Authorization Check

3 properties

JSON SCHEMA

Flag

11 properties

JSON SCHEMA

FlagList

3 properties

JSON SCHEMA

GenerateLinkDto

6 properties

JSON SCHEMA

Group

7 properties

JSON SCHEMA

GroupList

3 properties

JSON SCHEMA

IntentOptions

2 properties

JSON SCHEMA

JwksResponse

1 properties

JSON SCHEMA

JwtTemplate

4 properties

JSON SCHEMA

MagicAuth

8 properties

JSON SCHEMA

NewConnectApplicationSecret

7 properties

JSON SCHEMA

WorkOS Organization

8 properties

JSON SCHEMA

OrganizationApiKey

9 properties

JSON SCHEMA

OrganizationApiKeyList

3 properties

JSON SCHEMA

OrganizationApiKeyWithValue

10 properties

JSON SCHEMA

OrganizationDomainDataDto

2 properties

JSON SCHEMA

OrganizationDomainStandAlone

10 properties

JSON SCHEMA

OrganizationDto

6 properties

JSON SCHEMA

OrganizationList

3 properties

JSON SCHEMA

PaginationOrder

0 properties

JSON SCHEMA

PasswordReset

8 properties

JSON SCHEMA

PortalLinkResponse

1 properties

JSON SCHEMA

Profile

15 properties

JSON SCHEMA

RadarListEntryAlreadyPresentResponse

1 properties

JSON SCHEMA

RadarStandaloneResponse

5 properties

JSON SCHEMA

RedirectUri

6 properties

JSON SCHEMA

RedirectUriDto

2 properties

JSON SCHEMA

RemoveRoleDto

0 properties

JSON SCHEMA

ResendUserlandUserInviteOptionsDto

1 properties

JSON SCHEMA

ResetPasswordResponse

1 properties

JSON SCHEMA

Role

10 properties

JSON SCHEMA

RoleList

2 properties

JSON SCHEMA

SendEmailChangeDto

1 properties

JSON SCHEMA

SendVerificationEmailResponse

1 properties

JSON SCHEMA

SetRolePermissionsDto

1 properties

JSON SCHEMA

SlimRole

1 properties

JSON SCHEMA

SsoAuthorizeUrlResponse

1 properties

JSON SCHEMA

SsoIntentOptions

2 properties

JSON SCHEMA

SsoLogoutAuthorizeResponse

2 properties

JSON SCHEMA

SsoTokenResponse

5 properties

JSON SCHEMA

TokenQueryDto

4 properties

JSON SCHEMA

UpdateAuditLogsRetentionDto

1 properties

JSON SCHEMA

UpdateAuthorizationPermissionDto

2 properties

JSON SCHEMA

UpdateAuthorizationResourceDto

0 properties

JSON SCHEMA

UpdateGroupDto

2 properties

JSON SCHEMA

UpdateJwtTemplateDto

1 properties

JSON SCHEMA

UpdateOAuthApplicationDto

4 properties

JSON SCHEMA

UpdateOrganizationDto

7 properties

JSON SCHEMA

UpdateOrganizationRoleDto

2 properties

JSON SCHEMA

UpdateRoleDto

2 properties

JSON SCHEMA

UpdateUserlandUserDto

0 properties

JSON SCHEMA

UpdateWebhookEndpointDto

3 properties

JSON SCHEMA

WorkOS User

12 properties

JSON SCHEMA

UserApiKey

9 properties

JSON SCHEMA

UserApiKeyList

3 properties

JSON SCHEMA

UserApiKeyWithValue

10 properties

JSON SCHEMA

UserConsentOption

4 properties

JSON SCHEMA

UserlandAuthenticateResponse

8 properties

JSON SCHEMA

UserlandRevokeSessionDto

2 properties

JSON SCHEMA

UserlandUser

13 properties

JSON SCHEMA

UserlandUserAuthenticationFactorList

3 properties

JSON SCHEMA

UserlandUserInvite

15 properties

JSON SCHEMA

UserlandUserList

3 properties

JSON SCHEMA

UserlandUserOrganizationMembership

12 properties

JSON SCHEMA

UserManagementLoginRequest

3 properties

JSON SCHEMA

UserObject

5 properties

JSON SCHEMA

UserRoleAssignment

7 properties

JSON SCHEMA

UserRoleAssignmentList

3 properties

JSON SCHEMA

ValidateApiKeyDto

1 properties

JSON SCHEMA

VaultByokKeyProvider

0 properties

JSON SCHEMA

VerifyEmailAddressDto

1 properties

JSON SCHEMA

VerifyEmailResponse

1 properties

JSON SCHEMA

WaitlistUser

7 properties

JSON SCHEMA

WebhookEndpointJson

8 properties

JSON SCHEMA

WebhookEndpointList

3 properties

JSON SCHEMA

WidgetSessionTokenDto

3 properties

JSON SCHEMA

WidgetSessionTokenResponse

1 properties

JSON SCHEMA

Scroll within the panel for all 162 ·

JSON Structure 4

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Workos Audit Event Structure

0 properties

JSON STRUCTURE

Workos Organization Structure

0 properties

JSON STRUCTURE

Workos Structure

0 properties

JSON STRUCTURE

Workos User Structure

0 properties

JSON STRUCTURE

Examples 21

Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.

Example request and response payloads for these APIs.

Scroll within the panel for all 21 ·

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Workos Authentication

http · 1 scheme

SECURITY

Workos Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Workos Vulnerability Disclosure

disclosure policy published

SECURITY

Workos Trust Center

SOC 2, HIPAA, GDPR

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Workos Agentic Access

172 operations · 98 acting · 98 human-in-the-loop

172 operations · 98 acting

AGENTIC

Resources

Every other property we hold for WorkOS — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 3

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/workos · machine-readable index on apis.io