Skip to main content

AuthorizationServerMetadata

RFC 8414 authorization-server metadata. Field names are snake_case because the standard requires it, and the document is returned bare, not enveloped.

issuerstring

The authorization server's identifier — scheme and host, no path.

Example: https://api.service.app.uysot.uz
authorization_endpointstring

The browser URL of the consent page. Not GET /v1/open-api/oauth/authorize, which is the API that page calls.

Example: https://app.uysot.uz/oauth-consent.html
token_endpointstring
Example: https://api.service.app.uysot.uz/v1/open-api/oauth/token
revocation_endpointstring
Example: https://api.service.app.uysot.uz/v1/open-api/oauth/revoke
registration_endpointstringnullable

Dynamic registration (RFC 7591). Absent from the document entirely when dynamic registration is disabled on the deployment.

Example: https://api.service.app.uysot.uz/v1/open-api/oauth/register
scopes_supportedstring[]

Only PERMISSION_OPEN_API_MCP:READ is advertised — see the endpoint description for why the full permission matrix is deliberately not listed here.

Example: ["PERMISSION_OPEN_API_MCP:READ"]
response_types_supportedstring[]
Example: ["code"]
grant_types_supportedstring[]
Example: ["authorization_code","refresh_token"]
code_challenge_methods_supportedstring[]

PKCE methods. Only S256 — plain is not accepted.

Example: ["S256"]
token_endpoint_auth_methods_supportedstring[]

none is the public-client method: no secret, PKCE instead.

Example: ["client_secret_post","none"]
revocation_endpoint_auth_methods_supportedstring[]
Example: ["client_secret_post","none"]
AuthorizationServerMetadata
{
"issuer": "https://api.service.app.uysot.uz",
"authorization_endpoint": "https://app.uysot.uz/oauth-consent.html",
"token_endpoint": "https://api.service.app.uysot.uz/v1/open-api/oauth/token",
"revocation_endpoint": "https://api.service.app.uysot.uz/v1/open-api/oauth/revoke",
"registration_endpoint": "https://api.service.app.uysot.uz/v1/open-api/oauth/register",
"scopes_supported": [
"PERMISSION_OPEN_API_MCP:READ"
],
"response_types_supported": [
"code"
],
"grant_types_supported": [
"authorization_code",
"refresh_token"
],
"code_challenge_methods_supported": [
"S256"
],
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"none"
],
"revocation_endpoint_auth_methods_supported": [
"client_secret_post",
"none"
]
}