Authentication

Create a key under Account → API keys, then send it as a bearer token. X-API-Key and ?api_key= also work for quick tests.

curl -s https://authbeta.com/api/v1/status \
  -H "Authorization: Bearer ab_xxxxxxxxxxxxxxxxxxxx"

Base URL: https://authbeta.com/api/v1 · Every response is JSON with an ok flag.

Rate limits

Each key has its own per-minute budget (default 120). Responses carry X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset; going over returns 429 with a Retry-After header.

Errors

StatusMeaning
400A required field is missing.
401Key missing, invalid, disabled or expired.
403The key lacks the scope this endpoint needs.
404Unknown endpoint or vault entry.
422The input was understood but cannot be used.
429Rate limit exceeded.
503The API is switched off by the administrator.
{"ok": false, "error": "The \"secret\" field must be a valid base32 string."}

Endpoints

POST /totp scope: totp

Generate a code from a secret, otpauth link or free text.

Parameter Type Required Description
secret | uri | input string yes The base32 secret, an otpauth:// link, or text containing one.
digits int no 4-10, default 6
period int no Seconds, default 30
algorithm string no SHA1 | SHA256 | SHA512 | STEAM
counter int no Present = HOTP mode
timestamp int no Unix time to compute the code at
include_secret bool no Echo the secret back, default false
POST /totp/verify scope: totp

Check whether a code matches a secret.

Parameter Type Required Description
secret string yes Base32 secret
code string yes The code to verify
window int no Allowed drift in steps, 0-10, default 1
POST /totp/secret scope: totp

Create a new random secret and its otpauth link.

Parameter Type Required Description
bytes int no 10-64, default 20 (160 bit)
label string no Account name
issuer string no Service name
POST /totp/qr scope: totp

Render a QR code as PNG or SVG.

Parameter Type Required Description
text | secret string yes Arbitrary text, or a secret to build an otpauth link from
format string no png (default) or svg
scale int no 2-20, pixels per module
ecc string no L | M | Q | H
raw bool no Return the image itself instead of JSON
POST /totp/decode scope: totp

Read a QR image and return the 2FA data it holds.

Parameter Type Required Description
image string yes Base64 image data, with or without the data: prefix
POST /totp/bulk scope: totp

Codes for a whole list at once.

Parameter Type Required Description
text string yes One entry per line
delimiter string no auto (default), pipe, comma, tab, …
include_secret bool no Echo secrets back, default false
POST /password scope: password

Generate one or more passwords.

Parameter Type Required Description
mode string no random | memorable | pin | hex | base64 | uuid
length int no 4-256
quantity int no 1-50
lowercase, uppercase, digits, symbols bool no Character sets for random mode
exclude_ambiguous, no_repeat, no_sequential bool no Extra rules
words int no 2-12 for memorable mode
POST /password/strength scope: password

Score a password.

Parameter Type Required Description
password string yes The password to analyse
GET /ip/{ip} scope: ip

Details for an IP address. Without {ip}, your own address is used.

GET /dns scope: ip

DNS records for a hostname.

Parameter Type Required Description
host string yes Domain name
type string no Comma separated list, default A,AAAA,MX,NS,TXT
GET /whois scope: ip

WHOIS data for a domain or IP.

Parameter Type Required Description
query string yes Domain or IP
POST /ports scope: ip

Check whether TCP or UDP ports accept traffic. TCP returns open/closed/filtered; UDP returns open, closed (ICMP unreachable) or open|filtered when the port stays silent.

Parameter Type Required Description
host string yes Hostname or IP address
protocol string no tcp (default) or udp
ports array|string no List of ports, or "53,123,161". Defaults to the common ports for the chosen protocol.
GET /email-security scope: ip

SPF, DMARC, MX, MTA-STS and TLS-RPT for a domain.

Parameter Type Required Description
domain string yes Domain name
POST /text scope: text

Run a text operation.

Parameter Type Required Description
text string yes Input text
operation string yes See the list of operations below
mixed no Operation specific parameters (delimiter, column, find, replace…)
GET /vault scope: vault

List your saved 2FA accounts with current codes.

GET /vault/{id}/code scope: vault

Current code for one vault entry. HOTP entries advance the counter.

GET /status

Details about the key you are using.

Example

curl -s https://authbeta.com/api/v1/totp \
  -H "Authorization: Bearer ab_xxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{"secret":"JBSWY3DPEHPK3PXP","digits":6}'

{
  "ok": true,
  "result": {
    "issuer": "", "label": "", "digits": 6, "period": 30,
    "algorithm": "SHA1", "type": "totp",
    "code": "123456", "next_code": "654321",
    "expires_in": 17, "server_time": 1771200000
  }
}

Text operations

Values accepted by the operation field of POST /text:

trim_lines remove_empty remove_duplicates sort_asc sort_desc sort_natural sort_length shuffle reverse_lines reverse_text number_lines unique_count extract_column replace_delimiter add_prefix_suffix wrap_lines find_replace regex_replace upper lower title sentence camel snake kebab toggle_case remove_spaces collapse_spaces remove_accents slugify base64_encode base64_decode url_encode url_decode html_encode html_decode hex_encode hex_decode json_escape json_pretty json_minify extract_emails extract_urls extract_ips extract_numbers extract_secrets hash_md5 hash_sha1 hash_sha256 hash_sha512 hash_crc32 join_lines split_length count_stats