CustomDomain™ docs
API referenceAgents

Start an agent authorization (code with PKCE)

GET
/oauth/agent/authorize

The authorization endpoint. A browser is sent here by an agent; the request is validated (the client, the exact redirect URI, S256 PKCE, the scopes, the resource) and the browser is redirected to the console, where a signed in owner or admin sees what the agent asks for and where its code would go, and approves or denies. The authorization code goes to the redirect URI and is exchanged at POST /oauth/agent/token. A request with an unregistered or mismatched redirect URI is refused without redirecting. client_id is a registered client or an https URL of a Client ID Metadata Document.

Query Parameters

client_id*string
redirect_uri*string
Formaturi
response_type*"code"

Value in

  • "code"
code_challenge*string

BASE64URL(SHA-256(code_verifier)).

code_challenge_method*"S256"

Value in

  • "S256"
scope*string

Space separated scopes from domains:read, domains:connect, domains:disconnect and domains:purchase. The person may approve fewer.

state?string
resource?string

RFC 8707. The resource the token is for: the MCP endpoint (https://mcp.customdomain.ai/mcp, the default) or this API's origin. Anything else is invalid_target. The access token carries it as aud.

Formaturi

Response Body

application/json

application/json

curl -X GET "https://example.com/oauth/agent/authorize?client_id=string&redirect_uri=http%3A%2F%2Fexample.com&response_type=code&code_challenge=string&code_challenge_method=S256&scope=string"
Empty
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}