OAuth
OAuth 2.0 endpoints for PUBLIC (third-party) applications — exchange an
authorization code, refresh an access token, revoke a token, and register a client
dynamically.
Errors on /oauth/token, /oauth/revoke and /oauth/register are not wrapped in
the standard envelope: they use the RFC 6749 §5.2 / RFC 7591 §3.2.2 shape
(error, error_description) with a non-standard message_code added so existing
integrations can keep branching on the same numeric code.
Exchange Token
The OAuth 2.0 token endpoint (RFC 6749). A confidential client must call it from **your
Revoke Token
Revoke one of your own tokens (RFC 7009). Revoking a **refresh token** (`uysotrt_…`) also
Register Client
Dynamic client registration (RFC 7591). An MCP client that has no `client_id` of its own