Integrate an agent
Register an agent identity and exchange it for access to the MCP resource.
Integrate an agent
The service publishes a machine-readable protocol at /auth.md. Fetch it and
the OAuth discovery documents at runtime instead of hard-coding deployment
URLs.
Discover
Fetch:
GET /auth.md
GET /.well-known/oauth-protected-resource
GET /.well-known/oauth-authorization-serverThe protected resource is /mcp. The advertised scopes and endpoints in the
responses are authoritative for the deployment.
Register
POST /agent/identity accepts one of these methods:
anonymous— creates a pre-claim credential and a claim ceremony token.service_auth— starts a user-code ceremony for a suppliedlogin_hint.identity_assertion— exchanges a trusted, audience-bound ID-JAG for a service identity assertion.
The response describes whether a claim is required. Never ask the user to send the claim code back to the agent; the user enters it on the verification page.
Exchange and use credentials
Post the returned identity assertion to the advertised token endpoint using the
RFC 7523 JWT-bearer grant. Claim ceremonies use the advertised claim grant and
polling interval. On success, send the resulting bearer token to /mcp.
There is no refresh token. Re-exchange a still-valid identity assertion or restart registration when it expires. Use the advertised revocation endpoint when a credential should no longer be accepted.
For complete error codes, expiry behavior, and polling semantics, follow the
generated /auth.md document.