Reference
The IAM API hub.
Canonical reference catalog of major IAM vendor APIs — Okta, Entra Graph, SailPoint, CyberArk, Auth0, Saviynt, PingOne, BeyondTrust. Base URLs, auth methods, method counts.
- Okta Workforce + CICREST95+ methods
- Base URL
https://{yourOktaDomain}/api/v1/- Auth
- API Token or OAuth 2.0
Recent
- Identity Threat Protection — adaptive risk-policy event types added.
- WebAuthn enrollment now supports attestation conveyance preference per-policy.
- Provisioning Inbound — SCIM filter support for ne (not-equal) operator GA.
- Microsoft Entra (Graph API)REST200+ methods
- Base URL
https://graph.microsoft.com/v1.0/- Auth
- OAuth 2.0 (delegated or app-only)
Recent
- Conditional Access — token-protection policy GA.
- External ID — pricing announced post-preview.
- Entra ID Governance — access reviews recurrence flexibility added.
- SailPoint Identity Security CloudREST140+ methods
- Base URL
https://{tenant}.api.identitynow.com/v3/- Auth
- OAuth 2.0 client credentials
Recent
- Access modeling AI — new exclusion-recommendation endpoints.
- Workflows — event-based triggers for certification campaigns.
- Connectors — Workday HCM connector v2 GA.
- CyberArk Identity + Privilege CloudREST110+ methods
- Base URL
https://{tenant}.id.cyberark.cloud/api/- Auth
- OAuth 2.0 client credentials
Recent
- Identity Security Insights — new threat-event API endpoint.
- Secure Web Sessions — policy API expanded with device-posture conditions.
- Conjur — new ephemeral-secret rotation interval policy.
- Auth0 / Okta CICREST80+ methods
- Base URL
https://{tenant}.auth0.com/api/v2/- Auth
- OAuth 2.0 management tokens
Recent
- Forms — new condition operator for ELS rules.
- Custom Domains — per-tenant cert auto-rotate window narrowed.
- Actions runtime — Node 22 LTS GA.
- Saviynt Enterprise Identity CloudREST90+ methods
- Base URL
https://{tenant}.saviyntcloud.com/ECM/api/- Auth
- JWT bearer
Recent
- New /api/v5/userimports for high-throughput delta ingestion.
- Risk-based access certification — recommender API GA.
- Connector framework — generic REST connector now supports OAuth 2.0 PKCE.
- PingOne (Workforce + DaVinci)REST130+ methods
- Base URL
https://api.pingone.com/v1/- Auth
- OAuth 2.0
Recent
- DaVinci — new pre-built node for AAL3 step-up.
- PingOne Verify — biometric template expiration policy GA.
- PingOne Authorize — Cedar policy support GA.
- BeyondTrust (Password Safe + Privileged Remote Access)REST70+ methods
- Base URL
https://{appliance}/BeyondTrust/api/public/v3/- Auth
- API Key + IP allowlist
Recent
- Smart Rules — new condition family for cloud-asset tags.
- Privileged Remote Access — Jumpoint API for cloud workloads.
- Endpoint Privilege Management — policy export API.
Engineering
Building on these APIs?
We ship custom IAM integrations across all 8 of these surfaces. Our engineers carry the vendor certs that make audit-defensibility cheap.