NylorunDocsBeta
Management APIVaultsCredentials

Finish an MCP OAuth connect

GET
/v1/oauth/callback

Where the authorization server sends the browser back with code and state (or error). Exchanges the code once and stores the credential; answers a small HTML page. Needs no credential and no Nylorun-Protocol. A state is used once, for ten minutes (oauth_state_invalid).

Authorization

headerAuthorizationBearer <token>

An application key of the Tenant (PUT /v1/tenant/keys/{keyId}), or Studio's key, derived from the admin key. With Nylorun-Subject and Nylorun-Scopes, it acts for that person, narrowed to those scopes. Never accepted from a browser (Origin).

Query Parameters

code?string
state?string
error?string

Header Parameters

Nylorun-Protocol?string

The protocol version, 8

Nylorun-Subject?string

The person an application key acts for

Nylorun-Scopes?string

The subject's space-separated scopes; required with a subject

Response Body

Connected

response?stringtext/html
curl -X GET "https://example.com/v1/oauth/callback"
"string"