Authentication & Authorization — entry 004 of 4
Stytch
Stytch provides passwordless authentication primitives — email magic links, SMS/WhatsApp OTP, passkeys, and OAuth social login — plus session and user management for consumer and B2B apps. API calls are authenticated with HTTP Basic Auth using a project's project_id as the username and its secret as the password against api.stytch.com, separate from the OAuth2 client-credentials scheme used only by its M2M Connected Apps endpoints. Stytch offers a free tier for early-stage usage alongside usage-based paid plans.
AuthenticationBasic AuthSign up with the provider to obtain credentials.
HTTPSSupportedTraffic is encrypted in transit.
CORSDisabledBrowser calls need a server-side proxy.
PricingFreemiumA usable free tier exists, with paid plans for more volume.
FormatsJSONResponses can be requested as JSON.
GreatAPIs Score
Score75
Authentication15/25Basic Auth credentials required
Pricing17/20Freemium tier available
Docs14/20Documentation URL provided
Formats9/15Single response format
Freshness20/20Verified within 6 months
Auth quickstart
- Sign up with the provider to get an API key.
- Send it on every request as a header
Authorization: <key> - The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Stored keyNo key stored
Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.