REST — /api/mcp
9 route handlers under /api/mcp · 9 public (auth-optional).
Public flags are cross-referenced against
PUBLIC_API_PREFIXESinsrc/lib/route-access.ts. Routes without a public prefix require an authenticated session (or, where applicable, a signed federation request). See Auth models.
| Route | Methods | Access | Description |
|---|---|---|---|
/api/mcp | GET POST OPTIONS | Public | JSON-RPC code handleMcpRequest returns for an unauthenticated call. |
/api/mcp/device/approve | POST | Public | POST /api/mcp/device/approve — act on a pending device-code authorization. |
/api/mcp/device/code | POST | Public | POST /api/mcp/device/code — RFC 8628 device authorization endpoint. |
/api/mcp/device/token | POST | Public | POST /api/mcp/device/token — RFC 8628 token polling endpoint. |
/api/mcp/oauth/authorize | POST | Public | POST target for the consent form — mints the authorization code. |
/api/mcp/oauth/register | POST | Public | RFC 7591 — OAuth 2.0 Dynamic Client Registration. |
/api/mcp/oauth/token | POST | Public | OAuth 2.1 token endpoint for the MCP surface. |
/api/mcp/token | GET POST | Public | POST /api/mcp/token — issue a scoped MCP bearer token. |
/api/mcp/token/revoke | POST | Public | POST /api/mcp/token/revoke — revoke a previously-issued MCP bearer token. |