---
title: "Start the vendor OAuth flow for an MCP server connection."
method: POST
path: "/mcpservers/oauth/start"
tags: ["AI"]
---

# Start the vendor OAuth flow for an MCP server connection.

`POST /mcpservers/oauth/start`

Starts a vendor-fixed OAuth 2.1 authorization-code + PKCE flow so the authenticated customer can connect a GitHub or Linear account to an MCP server without ever handling a client_id/client_secret. Returns the vendor's authorize_url to redirect the user's browser to, plus a link_token used to correlate the eventual POST /mcpservers/oauth/complete call back to this flow.

## Request body

- object
  - `vendor` 'github' | 'linear', required — The OAuth vendor to connect to.
  - `mcp_server_id` string, uuid — Optional. The ID of an existing customer-owned MCP server (returned from a prior POST /mcpservers response) to reconnect/refresh OAuth credentials for. Omit to create a new MCP server on completion.

## Response `200`

The vendor authorize URL and a correlating link token.

- object
  - `authorize_url` string, uri — Redirect the user's browser here to start the vendor's consent screen.
  - `link_token` string — Opaque token correlating this flow to the later POST /mcpservers/oauth/complete call.

## Other responses

- `400` — Invalid request (INVALID_ARGUMENT).
- `401` — Authentication required (UNAUTHENTICATED).
- `404` — Resource not found (NOT_FOUND).
- `500` — Internal error (INTERNAL).

## Changes

- **2026-09-12** `a5e92b1a8467` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/voipbin/apis/voipbin-api/changes/mcpservers/oauth/start/post.md)

---

[API](https://skmtc.dev/voipbin/apis/voipbin-api.md) · [All operations](https://skmtc.dev/voipbin/apis/voipbin-api/llms.txt) · [OpenAPI document](https://skmtc.dev/voipbin/apis/voipbin-api/revisions/6a2b13260ccc?raw)
