Start an MCP OAuth connect
Signs the installation in to the remote MCP server at url (declared as server) and stores its OAuth credential, bound to url, in this installation vault. The Runtime discovers the server's authorization server (RFC 9728, RFC 8414), registers itself (RFC 7591) unless clientId names a registered client, and answers the URL to open in a browser; the sign-in returns to GET /v1/oauth/callback within expiresAt. The callback URL is NYLORUN_PUBLIC_URL + /v1/oauth/callback, or this request's own origin when the Host has no public URL. Application keys acting for no one only. oauth_client_required when the server offers no registration and no clientId was given.
managementKeyAuthorizationBearer <token>A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).
vaultId*stringNylorun-Protocol*stringThe protocol version, 8
application/json- body
url*string1 <= length <= 2048server*string1 <= length <= 128clientId?string1 <= length <= 512Where to send the browser
application/json- response
authorizeUrl*stringexpiresAt*stringimport { createAdmin } from "@nylorun/admin";const admin = createAdmin();const { authorizeUrl } = await admin.vaults.startOAuth("vlt_123", { url: "https://mcp.linear.app/mcp", server: "linear",});{ "authorizeUrl": "string", "expiresAt": "string"}Delete a credential DELETE
Previous Page
Finish an MCP OAuth connect GET
Where the authorization server sends the browser back with `code` and `state` (or `error`). Exchanges the code once and stores the credential; answers a small HTML page. Needs no credential and no `Nylorun-Protocol`. A `state` is used once, for ten minutes (`oauth_state_invalid`).