Skip to content
Proud to collaborate with Microsoft for Startups

agents.mcp-server.discover-auth ​

Discover an MCP server's OAuth authorization server (RFC 9728/8414) and stage a connection for consent. Reuses an existing DCR client and user grant; pass reauthorize=true only to rotate the client (wipes tokens).

Discover an MCP server's OAuth setup and stage a connection for consent.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-agents
Version1.0

Triggers ​

SourceEndpoint / EventDescription
APIPOST /api/agents/mcp-servers/discover-authAPI — discover an MCP server's authorization server

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuidstringYes——
mcp_server_uuidstringYes——
redirect_uristringYes—Callback URL the browser returns to after consent
connection_namestringNo—Name for the credential connection. Must stay stable across re-consent: connection.setup upserts by (organization, name).
scopesjsonNo——
reauthorizebooleanNo—When true, mint a new DCR client and wipe access/refresh tokens so the organization must consent again. Default false: reuse the existing client and keep the grant.

Output Schema ​

FieldTypeRequiredDefaultDescription
errorstringNo——
error_typestringNo——
failed_atstringNo——
failed_at_statestringNo——
failed_layerjsonNo——
failed_stepstringNo——
failure_reasonstringNo——
mcp_server_uuidjsonNo——
organization_uuidjsonNo——
connection_uuidstringNo——
connection_namestringNo——
oauth_supportedbooleanNo——
authorize_endpointstringNo——
token_endpointstringNo——
authorization_serverstringNo——
registered_via_dcrbooleanNo——
client_idstringNo——
scopesjsonNo——
detailstringNo——
redirect_uristringNo——
reauthorizebooleanNo——
reused_existing_clientbooleanNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—run—
runNoNo—complete—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
initiatedrunrun—
runcompletecompleted—
* (any state)failfailed—

Outcomes ​

OutcomeTypeDescriptionState Data Keys
discoveredSUCCESSMCP authorization server discoveredmcp_server_uuid, connection_uuid, authorize_endpoint, oauth_supported
failedFAILUREMCP authorization server discovered failedfailure_reason, error, error_type, failed_at_state, failed_step, failed_layer

Business Errors ​

CodeMessage Template
AGENTS_ORGANIZATION_CONTEXT_INVALIDAuthenticated organization context is missing or does not match the workflow input
AGENTS_MCP_SERVER_NOT_FOUNDMCP server {mcp_server_uuid} was not found in the organization
AGENTS_MCP_AUTH_REJECTEDMCP server {mcp_server_uuid} rejected the stored credential
AGENTS_MCP_AUTH_EXPIREDThe OAuth grant for MCP server {mcp_server_uuid} has expired and cannot be refreshed; the organization must re-authorize it
AGENTS_VALIDATION_FAILEDWorkflow input or domain state failed validation:
AGENTS_CONFLICTConflicting agent domain state:
AGENTS_PROVIDER_FAILEDUpstream provider or runner call failed:
AGENTS_MCP_CALL_FAILEDMCP tool call failed for {tool_name}:

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "agents.mcp-server.discover-auth",
  "initial_data": {
    "organization_uuid": "value",
    "mcp_server_uuid": "value",
    "redirect_uri": "value"
  }
}