Authentication & Authorization — entry 004 of 4

Stytch

Verified Jul 2026

Stytch provides passwordless authentication primitives — email magic links, SMS/WhatsApp OTP, passkeys, and OAuth social login — plus session and user management for consumer and B2B apps. API calls are authenticated with HTTP Basic Auth using a project's project_id as the username and its secret as the password against api.stytch.com, separate from the OAuth2 client-credentials scheme used only by its M2M Connected Apps endpoints. Stytch offers a free tier for early-stage usage alongside usage-based paid plans.

authenticationpasswordlessmfassouser-management
AuthenticationBasic AuthSign up with the provider to obtain credentials.
HTTPSSupportedTraffic is encrypted in transit.
CORSDisabledBrowser calls need a server-side proxy.
PricingFreemiumA usable free tier exists, with paid plans for more volume.
FormatsJSONResponses can be requested as JSON.

GreatAPIs Score

Score75out of 100
Authentication15/25Basic Auth credentials required
Pricing17/20Freemium tier available
Docs14/20Documentation URL provided
Formats9/15Single response format
Freshness20/20Verified within 6 months

Embed this badge

Scored 75 on greatapis.com
<a href="https://greatapis.com/api/stytch/"><img src="https://greatapis.com/badge/stytch.svg" alt="Scored 75 on greatapis.com"></a>

Auth quickstart

  1. Sign up with the provider to get an API key.
  2. Send it on every request as a headerAuthorization: <key>
  3. The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Stored keyNo key stored

Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.