Finish an MCP OAuth connect
Where the authorization server sends the browser back with code and state (or error). Exchanges the code once and stores the credential; answers a small HTML page. Needs no credential and no Nylorun-Protocol. A state is used once, for ten minutes (oauth_state_invalid).
AuthorizationBearer <token>An application key of the Tenant (PUT /v1/tenant/keys/{keyId}), or Studio's key, derived from the admin key. With Nylorun-Subject and Nylorun-Scopes, it acts for that person, narrowed to those scopes. Never accepted from a browser (Origin).
code?stringstate?stringerror?stringNylorun-Protocol?stringThe protocol version, 8
Nylorun-Subject?stringThe person an application key acts for
Nylorun-Scopes?stringThe subject's space-separated scopes; required with a subject
Connected
response?stringtext/htmlcurl -X GET "https://example.com/v1/oauth/callback""string"Start an MCP OAuth connect POST
Signs the installation in to the remote MCP server at `url` (declared as `server`) and stores its OAuth credential, bound to `url`, in this installation vault. The Runtime discovers the server's authorization server (RFC 9728, RFC 8414), registers itself (RFC 7591) unless `clientId` names a registered client, and answers the URL to open in a browser; the sign-in returns to `GET /v1/oauth/callback` within `expiresAt`. The callback URL is `NYLORUN_PUBLIC_URL` + `/v1/oauth/callback`, or this request's own origin when the Host has no public URL. Application keys acting for no one only. `oauth_client_required` when the server offers no registration and no `clientId` was given.
Get the Tenant's sandbox configuration GET
Next Page