Start an agent authorization (code with PKCE)
The authorization endpoint. A browser is sent here by an agent; the request is validated (the client, the exact redirect URI, S256 PKCE, the scopes, the resource) and the browser is redirected to the console, where a signed in owner or admin sees what the agent asks for and where its code would go, and approves or denies. The authorization code goes to the redirect URI and is exchanged at POST /oauth/agent/token. A request with an unregistered or mismatched redirect URI is refused without redirecting. client_id is a registered client or an https URL of a Client ID Metadata Document.
Query Parameters
uriValue in
- "code"
BASE64URL(SHA-256(code_verifier)).
Value in
- "S256"
Space separated scopes from domains:read, domains:connect, domains:disconnect and domains:purchase. The person may approve fewer.
RFC 8707. The resource the token is for: the MCP endpoint (https://mcp.customdomain.ai/mcp, the default) or this API's origin. Anything else is invalid_target. The access token carries it as aud.
uriResponse Body
application/json
application/json
curl -X GET "https://example.com/oauth/agent/authorize?client_id=string&redirect_uri=http%3A%2F%2Fexample.com&response_type=code&code_challenge=string&code_challenge_method=S256&scope=string"{ "code": "string", "title": "string", "details": "string"}{ "code": "string", "title": "string", "details": "string"}