> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onecortex.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Read where an MCP client signs in

> The OAuth protected resource metadata (RFC 9728) an MCP client reads after a `401`: the agent's MCP URL, and Onecortex as the server that issues tokens for it. No key needed. A deleted, suspended or never deployed agent answers `404`. See [MCP](/call/mcp#signing-in).




## OpenAPI

````yaml /openapi.yaml get /.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp
openapi: 3.1.0
info:
  title: Onecortex API
  version: '1'
  description: >-
    Call a deployed agent over invoke, AG-UI or A2A, and read its public A2A
    Agent Card. This is the whole public API.
servers:
  - url: https://api.onecortex.io
security:
  - apiKey: []
paths:
  /.well-known/oauth-protected-resource/v1/agents/{agentId}/mcp:
    get:
      summary: Read where an MCP client signs in
      description: >
        The OAuth protected resource metadata (RFC 9728) an MCP client reads
        after a `401`: the agent's MCP URL, and Onecortex as the server that
        issues tokens for it. No key needed. A deleted, suspended or never
        deployed agent answers `404`. See [MCP](/call/mcp#signing-in).
      operationId: getMcpSignInMetadata
      parameters:
        - $ref: '#/components/parameters/AgentId'
      responses:
        '200':
          description: The metadata. Cached for 30 seconds.
          content:
            application/json:
              schema:
                type: object
                additionalProperties: true
              example:
                resource: >-
                  https://api.onecortex.io/v1/agents/agt_01K0000000000000000000000/mcp
                authorization_servers:
                  - https://app.onecortex.io
                scopes_supported:
                  - agent:invoke
                bearer_methods_supported:
                  - header
        '404':
          description: No such agent, or it is not serving.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorBody'
        '429':
          description: Over 60 requests a minute from one address.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorBody'
      security: []
components:
  parameters:
    AgentId:
      name: agentId
      in: path
      required: true
      description: The agent's ID, from its page in the dashboard.
      schema:
        type: string
        example: agt_01K0000000000000000000000
  schemas:
    ErrorBody:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - requestId
          properties:
            code:
              type: string
              enum:
                - validation_failed
                - invalid_request
                - unauthenticated
                - forbidden
                - organization_suspended
                - not_found
                - agent_not_ready
                - agent_not_deployed
                - agent_deleted
                - payload_too_large
                - rate_limited
                - internal_error
                - agent_error
                - upstream_error
                - service_unavailable
                - agent_unavailable
                - capacity_exceeded
            message:
              type: string
            details:
              type: object
              additionalProperties: true
            requestId:
              type: string
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        An Onecortex API key, `oc_live_...`, from API keys in the dashboard, or
        an access token, `oc_oat_...`, that an app received when a person
        allowed it to use one agent.

````