v2
mcp
mcp

Exchange OAuth code for MCP tokens

Exchange the authorization code for tokens and store the credential.

The frontend calls this after receiving the OAuth code from the popup. On success, subsequent /discover-tools calls for the same server URL will automatically use the stored credential.

post/api/mcp/oauth/callback

Request body

codestring required

Authorization code from OAuth callback

state_tokenstring required

State token for CSRF verification

Response

Successful Response

idstring required
providerstring required
type'api_key' | 'oauth2' | 'user_password' | 'host_scoped' | 'device_code' required
titlestring nullable required
scopesstring[] nullable required
usernamestring nullable required
hoststring nullable

Host pattern for host-scoped or MCP server URL for MCP credentials

is_managedboolean

Changes

Changed in 1 of the 92 revisions of this API.1

    • added the new device_code enum value to the type response property for the response status 200

      response-property-enum-value-added