OAuth and Original Connect
Original acts as an OAuth 2.0 / OpenID Connect authorization server. External apps and agent platforms (for example MCP clients) can let users sign in with their Original account and act on their behalf, using the Original Connect SDK or any standard OAuth client.
Supported standards
| Standard | What it covers |
|---|---|
| RFC 6749 | OAuth 2.0 framework (authorization code and refresh token grants) |
| RFC 7636 | PKCE, mandatory for every client, S256 only |
| RFC 7591 | Dynamic Client Registration: apps register themselves without admin help |
| RFC 8414 | Authorization Server Metadata (/.well-known/oauth-authorization-server) |
| OpenID Connect | ID token (RS256), discovery (/.well-known/openid-configuration), UserInfo |
| RFC 7009 | Token revocation |
Endpoints
All endpoints are relative to https://ai.original.land.
| Endpoint | Purpose |
|---|---|
GET /.well-known/oauth-authorization-server | Server metadata (used by MCP clients) |
GET /.well-known/openid-configuration | Same metadata, OpenID Connect location |
POST /oauth/register | Dynamic client registration |
GET /oauth/authorize | User sign-in and consent |
POST /oauth/token | Exchange a code or refresh token for tokens |
POST /oauth/revoke | Revoke a refresh token |
GET /oauth/userinfo | Signed-in user profile |
GET /oauth/jwks | Public keys to verify ID and access tokens |
Start from the discovery document. Most OAuth libraries only need the issuer URL and configure everything else automatically.
Register a client (RFC 7591)
Send a JSON body to POST /oauth/register:
{
"client_name": "My App",
"redirect_uris": ["https://myapp.example.com/callback"],
"token_endpoint_auth_method": "none",
"grant_types": ["authorization_code", "refresh_token"],
"scope": "openid profile agent.chat:<agentId>"
}
| Field | Notes |
|---|---|
client_name | Required, up to 200 characters |
redirect_uris | Required, 1 to 20 URLs. Redirects must match exactly |
token_endpoint_auth_method | none (public client, default) or client_secret_post (confidential client) |
grant_types | Include refresh_token to receive refresh tokens as a public client |
scope | Space-separated. Scopes not allowed for dynamic clients are dropped |
client_uri, logo_uri, contacts | Optional metadata |
The response (201) contains a client_id (prefix oc_). Confidential clients also receive a client_secret (prefix ocs_) that never expires.
The client_secret is shown only once in the registration response. Store it securely.
Registrations are rate limited: a 429 too_many_requests response means you should retry later.
Scopes
| Scope | Meaning | Dynamic clients |
|---|---|---|
openid | Issue an ID token and allow UserInfo | Yes |
profile | Email, name, picture, plan, and credits | Yes |
agent.chat:<agentId> | Chat with a specific agent on the user's behalf | Yes |
agent.purchase | Buy plans or redeem vouchers for agents | Yes |
workspace | Privileged workspace access | No, requires manual registration by the Original team |
If no scope is requested, the client gets openid profile.
Authorization flow
- Redirect the user to
/oauth/authorizewithresponse_type=code,client_id,redirect_uri,scope,state, optionalnonce,code_challenge, andcode_challenge_method=S256. - The user signs in, picks the account, and approves the consent screen.
- Original redirects back to
redirect_uriwithcodeandstate, or witherror=access_deniedif the user declines. - Call
POST /oauth/token(form-encoded) withgrant_type=authorization_code,code,redirect_uri,client_id,code_verifier, andclient_secretfor confidential clients.
Token lifetimes
| Token | Lifetime |
|---|---|
| Authorization code | 60 seconds, single use |
| Access token | 1 hour |
| Refresh token (confidential client) | 30 days |
| Refresh token (public client) | 7 days |
Refresh tokens rotate: every grant_type=refresh_token call returns a new refresh token and invalidates the old one. Public clients get refresh tokens only if they registered with the refresh_token grant type.
UserInfo
GET /oauth/userinfo with Authorization: Bearer <access_token> requires the openid scope. With profile it also returns email, name, picture, the platform plan and credits, unlocked agents, and active agent subscriptions.