Read where an MCP client signs in
import requests
url = "https://api.onecortex.io/.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp"
response = requests.get(url)
print(response.text)const options = {method: 'GET'};
fetch('https://api.onecortex.io/.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request GET \
--url https://api.onecortex.io/.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp{
"resource": "https://api.onecortex.io/v1/agents/agt_01K0000000000000000000000/mcp",
"authorization_servers": [
"https://app.onecortex.io"
],
"scopes_supported": [
"agent:invoke"
],
"bearer_methods_supported": [
"header"
]
}{
"error": {
"code": "validation_failed",
"message": "<string>",
"requestId": "<string>",
"details": {}
}
}{
"error": {
"code": "validation_failed",
"message": "<string>",
"requestId": "<string>",
"details": {}
}
}Endpoints
Read where an MCP client signs in
The OAuth protected resource metadata (RFC 9728) an MCP client reads after a 401: the agent’s MCP URL, and Onecortex as the server that issues tokens for it. No key needed. A deleted, suspended or never deployed agent answers 404. See MCP.
GET
/
.well-known
/
oauth-protected-resource
/
v1
/
agents
/
{agentId}
/
mcp
Read where an MCP client signs in
import requests
url = "https://api.onecortex.io/.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp"
response = requests.get(url)
print(response.text)const options = {method: 'GET'};
fetch('https://api.onecortex.io/.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request GET \
--url https://api.onecortex.io/.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp{
"resource": "https://api.onecortex.io/v1/agents/agt_01K0000000000000000000000/mcp",
"authorization_servers": [
"https://app.onecortex.io"
],
"scopes_supported": [
"agent:invoke"
],
"bearer_methods_supported": [
"header"
]
}{
"error": {
"code": "validation_failed",
"message": "<string>",
"requestId": "<string>",
"details": {}
}
}{
"error": {
"code": "validation_failed",
"message": "<string>",
"requestId": "<string>",
"details": {}
}
}Path Parameters
The agent's ID, from its page in the dashboard.
Example:
"agt_01K0000000000000000000000"
Response
The metadata. Cached for 30 seconds.
The response is of type object.
Last modified on September 30, 2026