NylorunDocsBeta
Management APIVaultsCredentials

Start an MCP OAuth connect

POST
/v1/tenant/vaults/{vaultId}/oauth/start

Signs the installation in to the remote MCP server at url (declared as server) and stores its OAuth credential, bound to url, in this installation vault. The Runtime discovers the server's authorization server (RFC 9728, RFC 8414), registers itself (RFC 7591) unless clientId names a registered client, and answers the URL to open in a browser; the sign-in returns to GET /v1/oauth/callback within expiresAt. The callback URL is NYLORUN_PUBLIC_URL + /v1/oauth/callback, or this request's own origin when the Host has no public URL. Application keys acting for no one only. oauth_client_required when the server offers no registration and no clientId was given.

Authorization

managementKey
headerAuthorizationBearer <token>

A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).

Path Parameters

vaultId*string

Header Parameters

Nylorun-Protocol*string

The protocol version, 8

Request Body

application/json
  1. body
url*string
Length1 <= length <= 2048
server*string
Length1 <= length <= 128
clientId?string
Length1 <= length <= 512

Response Body

Where to send the browser

application/json
  1. response
authorizeUrl*string
expiresAt*string
import { createAdmin } from "@nylorun/admin";const admin = createAdmin();const { authorizeUrl } = await admin.vaults.startOAuth("vlt_123", {  url: "https://mcp.linear.app/mcp",  server: "linear",});
{  "authorizeUrl": "string",  "expiresAt": "string"}