agents.mcp-server.discover-auth
Discover an MCP server's OAuth authorization server (RFC 9728/8414) and stage a connection for consent. Reuses an existing DCR client and user grant; pass reauthorize=true only to rotate the client (wipes tokens).
Discover an MCP server's OAuth setup and stage a connection for consent.
Overview
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-agents |
| Version | 1.0 |
Triggers
| Source | Endpoint / Event | Description |
|---|---|---|
| API | POST /api/agents/mcp-servers/discover-auth | API — discover an MCP server's authorization server |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | string | Yes | — | — |
mcp_server_uuid | string | Yes | — | — |
redirect_uri | string | Yes | — | Callback URL the browser returns to after consent |
connection_name | string | No | — | Name for the credential connection. Must stay stable across re-consent: connection.setup upserts by (organization, name). |
scopes | json | No | — | — |
reauthorize | boolean | No | — | When true, mint a new DCR client and wipe access/refresh tokens so the organization must consent again. Default false: reuse the existing client and keep the grant. |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
error | string | No | — | — |
error_type | string | No | — | — |
failed_at | string | No | — | — |
failed_at_state | string | No | — | — |
failed_layer | json | No | — | — |
failed_step | string | No | — | — |
failure_reason | string | No | — | — |
mcp_server_uuid | json | No | — | — |
organization_uuid | json | No | — | — |
connection_uuid | string | No | — | — |
connection_name | string | No | — | — |
oauth_supported | boolean | No | — | — |
authorize_endpoint | string | No | — | — |
token_endpoint | string | No | — | — |
authorization_server | string | No | — | — |
registered_via_dcr | boolean | No | — | — |
client_id | string | No | — | — |
scopes | json | No | — | — |
detail | string | No | — | — |
redirect_uri | string | No | — | — |
reauthorize | boolean | No | — | — |
reused_existing_client | boolean | No | — | — |
States
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
initiated | Yes | No | — | run | — |
run | No | No | — | complete | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram
Transitions
| From | Action | To | Description |
|---|---|---|---|
initiated | run | run | — |
run | complete | completed | — |
* (any state) | fail | failed | — |
Outcomes
| Outcome | Type | Description | State Data Keys |
|---|---|---|---|
discovered | SUCCESS | MCP authorization server discovered | mcp_server_uuid, connection_uuid, authorize_endpoint, oauth_supported |
failed | FAILURE | MCP authorization server discovered failed | failure_reason, error, error_type, failed_at_state, failed_step, failed_layer |
Business Errors
| Code | Message Template |
|---|---|
AGENTS_ORGANIZATION_CONTEXT_INVALID | Authenticated organization context is missing or does not match the workflow input |
AGENTS_MCP_SERVER_NOT_FOUND | MCP server {mcp_server_uuid} was not found in the organization |
AGENTS_MCP_AUTH_REJECTED | MCP server {mcp_server_uuid} rejected the stored credential |
AGENTS_MCP_AUTH_EXPIRED | The OAuth grant for MCP server {mcp_server_uuid} has expired and cannot be refreshed; the organization must re-authorize it |
AGENTS_VALIDATION_FAILED | Workflow input or domain state failed validation: |
AGENTS_CONFLICT | Conflicting agent domain state: |
AGENTS_PROVIDER_FAILED | Upstream provider or runner call failed: |
AGENTS_MCP_CALL_FAILED | MCP tool call failed for {tool_name}: |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "agents.mcp-server.discover-auth",
"initial_data": {
"organization_uuid": "value",
"mcp_server_uuid": "value",
"redirect_uri": "value"
}
}