{
 "categories": [
  "identity",
  "developer-tools"
 ],
 "deployment": "hybrid",
 "evidence": [
  {
   "date": "2026-09-09",
   "fact": "homepage",
   "note": "FusionAuth presents identity software for humans, services, and AI, API-driven by design, with self-hosted, dedicated, on-prem, hybrid, and air-gapped deployment.",
   "source": "https://fusionauth.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "vendor",
   "note": "The public homepage identifies the vendor and product as FusionAuth.",
   "source": "https://fusionauth.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "deployment",
   "note": "The homepage states you can run identity self-hosted, dedicated, on-prem, hybrid, or air-gapped, which is hybrid delivery.",
   "source": "https://fusionauth.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "platforms[0]",
   "note": "The product includes a hosted or self-hosted web admin UI.",
   "source": "https://fusionauth.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "platforms[1]",
   "note": "Pricing lists Linux-oriented deployables: ZIP, DEB, RPM, Docker, and Kubernetes, plus FusionAuth Cloud.",
   "source": "https://fusionauth.io/pricing",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "license",
   "note": "Community is free and unlimited for self-host. Paid Starter starts at $162/month billed annually. That is freemium.",
   "source": "https://fusionauth.io/pricing",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.api.exists",
   "note": "FusionAuth documents a REST API and publishes a table of API-key-guarded endpoints with HTTP methods.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.api.kinds[0]",
   "note": "API examples are HTTP calls that send JSON to paths such as /api/user on the FusionAuth host.",
   "source": "https://fusionauth.io/docs/apis/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.api.auth[0]",
   "note": "The primary method is an API key in the Authorization header. Keys can be tenant-scoped or global and limited by endpoint and HTTP method.",
   "source": "https://fusionauth.io/docs/apis/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.api.auth[1]",
   "note": "JWT Authentication accepts Authorization: Bearer from the Login API or an OAuth grant, or an access_token cookie.",
   "source": "https://fusionauth.io/docs/apis/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.api.auth[2]",
   "note": "Client Credentials exchanges entity credentials at /oauth2/token, then calls the API with Authorization: Bearer.",
   "source": "https://fusionauth.io/docs/apis/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.api.coverage",
   "note": "The opened table includes users, applications, tenants, groups, identity providers, themes, lambdas, webhooks, import, search, and system APIs with GET/POST/PUT/PATCH/DELETE where marked. Community pricing also states Full API Access.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.api.docs",
   "note": "Opened as the current API-key endpoint index. Per-resource pages are linked from https://fusionauth.io/docs/llms-apis.txt.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.exists",
   "note": "FusionAuth documents official client libraries as thin wrappers over the public REST API.",
   "source": "https://fusionauth.io/docs/llms-sdks.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.official",
   "note": "The vendor SDK index lists FusionAuth-maintained client libraries and higher-level SDKs on fusionauth.io.",
   "source": "https://fusionauth.io/docs/llms-sdks.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.languages[0]",
   "note": "Official TypeScript/JavaScript client is @fusionauth/typescript-client for Node and browsers.",
   "source": "https://fusionauth.io/docs/sdks/typescript",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.languages[1]",
   "note": "Official Python client is fusionauth-client on PyPI.",
   "source": "https://fusionauth.io/docs/sdks/python",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.languages[2]",
   "note": "Official Java client is io.fusionauth:fusionauth-java-client on Maven.",
   "source": "https://fusionauth.io/docs/sdks/java",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.languages[3]",
   "note": "The official SDK index lists a Go client library.",
   "source": "https://fusionauth.io/docs/llms-sdks.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.languages[4]",
   "note": "The official SDK index lists a PHP client library.",
   "source": "https://fusionauth.io/docs/llms-sdks.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.languages[5]",
   "note": "The official SDK index lists a Ruby client library.",
   "source": "https://fusionauth.io/docs/llms-sdks.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.sdk.languages[6]",
   "note": "The official SDK index lists a .NET Core client library.",
   "source": "https://fusionauth.io/docs/llms-sdks.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.mcp.first_party",
   "note": "FusionAuth documents a first-party API MCP server installed as npx @fusionauth/mcp-api, with source at github.com/FusionAuth/fusionauth-mcp-api.",
   "source": "https://fusionauth.io/docs/get-started/download-and-install/development/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.mcp.verdict",
   "note": "The vendor page presents the server as official FusionAuth MCP and marks it a preview release that may break or be discontinued.",
   "source": "https://fusionauth.io/docs/get-started/download-and-install/development/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.cli.exists",
   "note": "FusionAuth documents the official CLI, installed with npm i -g @fusionauth/cli, invoked as fusionauth.",
   "source": "https://fusionauth.io/docs/customize/cli",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "Vendor docs describe lambdas as pluggable JavaScript that run at points in the user lifecycle.",
   "source": "https://fusionauth.io/docs/llms-extend.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.extensibility.webhooks",
   "note": "POST /api/webhook creates a webhook with a required URL. Events are JSON HTTP POST callbacks.",
   "source": "https://fusionauth.io/docs/apis/webhooks/create-a-webhook",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.data_access.export[0]",
   "note": "API responses are JSON, as in the retrieve-user curl example.",
   "source": "https://fusionauth.io/docs/apis/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.data_access.import[0]",
   "note": "POST /api/user/import is listed as an API-key-authenticated user import endpoint. The CLI can generate import JSON.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.rpa.ui_stack[0]",
   "note": "The admin console is a web application. No UI probe was run.",
   "source": "https://fusionauth.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.rpa.drivability",
   "note": "No repeatable UI probe exists. API, SDK, CLI, and MCP documentation establish non-browser paths; drivability stays unknown.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.computer_use.viability",
   "note": "No computer-use probe artifact was produced. Viability stays unknown.",
   "source": "https://fusionauth.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Opened a real llms.txt that routes to docs/llms.txt, APIs, SDKs, pricing, and product pages.",
   "source": "https://fusionauth.io/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "verdict.best_path",
   "note": "The REST API is the machine contract and the broader surface. MCP is official preview and CLI is customization-scoped, so API is the best path at the high score.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "verdict.scores.api",
   "note": "Broad, documented, read/write REST with scoped API keys, JWTs, client credentials, official client libraries, and import. Licensed features remain plan-gated. Score 8.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "verdict.scores.mcp",
   "note": "Official API MCP with one tool per endpoint. Vendor-declared preview, local/dev only, API-key leakage risk, and ~200k token default toolset. Score 6.",
   "source": "https://fusionauth.io/docs/get-started/download-and-install/development/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "verdict.scores.cli",
   "note": "Official CLI with API-key auth for emails, themes, lambdas, and messages, plus import:generate. Not a general API CLI. Score 6.",
   "source": "https://fusionauth.io/docs/customize/cli",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "verdict.scores.overall",
   "note": "Overall equals the highest assessed path score (API 8).",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "freshness.watch[0].url",
   "note": "Opened as the current first-party API MCP guide, including preview warning, npx package, and USE_TOOLS.",
   "source": "https://fusionauth.io/docs/get-started/download-and-install/development/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "freshness.watch[1].url",
   "note": "Opened the vendor-owned fusionauth-mcp-api repository. README titles it a preview FusionAuth API MCP server.",
   "source": "https://github.com/FusionAuth/fusionauth-mcp-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "freshness.watch[2].url",
   "note": "Opened as the current API-key endpoint index.",
   "source": "https://fusionauth.io/docs/reference/api-endpoints",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "freshness.watch[3].url",
   "note": "Opened as the current API authentication guide.",
   "source": "https://fusionauth.io/docs/apis/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-09",
   "fact": "freshness.watch[4].url",
   "note": "Opened as the current official FusionAuth CLI documentation.",
   "source": "https://fusionauth.io/docs/customize/cli",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-09",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://fusionauth.io/docs/get-started/download-and-install/development/mcp-server"
   },
   {
    "type": "repo",
    "url": "https://github.com/FusionAuth/fusionauth-mcp-api"
   },
   {
    "type": "docs",
    "url": "https://fusionauth.io/docs/reference/api-endpoints"
   },
   {
    "type": "docs",
    "url": "https://fusionauth.io/docs/apis/authentication"
   },
   {
    "type": "docs",
    "url": "https://fusionauth.io/docs/customize/cli"
   }
  ]
 },
 "homepage": "https://fusionauth.io/",
 "id": "fusionauth",
 "license": "freemium",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "api-key",
    "jwt",
    "client-credentials"
   ],
   "coverage": "full",
   "docs": "https://fusionauth.io/docs/reference/api-endpoints",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "api-json"
   ],
   "import": [
    "api-json"
   ]
  },
  "extensibility": {
   "scripting": [
    "lambdas"
   ],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. FusionAuth's REST APIs, official client libraries, CLI, webhooks, lambdas, and preview API MCP server cover identity administration without browser control.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "javascript",
    "python",
    "java",
    "go",
    "php",
    "ruby",
    "dotnet"
   ],
   "official": true
  }
 },
 "name": "FusionAuth",
 "platforms": [
  "web",
  "linux"
 ],
 "related": {
  "alternatives": [
   "auth0",
   "okta",
   "stytch"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "FusionAuth",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": 6,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 8,
   "rpa": null
  },
  "summary": "FusionAuth is automatable today through a JSON REST API. The opened API-key endpoint table lists CRUD on users, applications, tenants, groups, identity providers, themes, lambdas, webhooks, and related admin resources, plus POST /api/user/import. Community pricing states Full API Access. Most secured calls send an API key in the Authorization header. Selected endpoints also accept a JWT from Login or an OAuth grant, HTTP Basic with username apikey, or a client-credentials Bearer token. Official client libraries exist for TypeScript/JavaScript, Python, Java, Go, PHP, Ruby, and .NET. The official @fusionauth/cli manages email templates, themes, lambdas, and message templates and can generate import JSON. It is not a full API client. Webhooks POST JSON events to a configured URL and can be created at POST /api/webhook. Lambdas are documented as pluggable JavaScript. A vendor-owned preview API MCP server is published as npx @fusionauth/mcp-api and documented on fusionauth.io. It maps each API operation to a tool (300-plus, about 200k tokens unless USE_TOOLS restricts prefixes). The vendor marks it preview, local/dev only, and requires handing the client an API key. A separate unauthenticated docs MCP at https://ai.fusionauth.dev/mcp/docs is documentation search, not the product API. This record is FusionAuth CIAM only. Oracle Fusion Cloud ERP is outside the boundary. Connector catalogs were not opened. Computer-use viability is unassessed. API scores 8 and is the best path. MCP scores 6 as a limited vendor preview. CLI scores 6 because it is official but customization-scoped.\n"
 }
}