AuthorizationServerMetadata
RFC 8414 authorization-server metadata. Field names are snake_case because the standard
requires it, and the document is returned bare, not enveloped.
issuerstring
The authorization server's identifier — scheme and host, no path.
Example:
https://api.service.app.uysot.uzauthorization_endpointstring
The browser URL of the consent page. Not GET /v1/open-api/oauth/authorize,
which is the API that page calls.
Example:
https://app.uysot.uz/oauth-consent.htmltoken_endpointstring
Example:
https://api.service.app.uysot.uz/v1/open-api/oauth/tokenrevocation_endpointstring
Example:
https://api.service.app.uysot.uz/v1/open-api/oauth/revokeregistration_endpointstringnullable
Dynamic registration (RFC 7591). Absent from the document entirely when dynamic registration is disabled on the deployment.
Example:
https://api.service.app.uysot.uz/v1/open-api/oauth/registerscopes_supportedstring[]
Only PERMISSION_OPEN_API_MCP:READ is advertised — see the endpoint description for
why the full permission matrix is deliberately not listed here.
Example:
["PERMISSION_OPEN_API_MCP:READ"]response_types_supportedstring[]
Example:
["code"]grant_types_supportedstring[]
Example:
["authorization_code","refresh_token"]code_challenge_methods_supportedstring[]
PKCE methods. Only S256 — plain is not accepted.
Example:
["S256"]token_endpoint_auth_methods_supportedstring[]
none is the public-client method: no secret, PKCE instead.
Example:
["client_secret_post","none"]revocation_endpoint_auth_methods_supportedstring[]
Example:
["client_secret_post","none"]AuthorizationServerMetadata
{
"issuer": "https://api.service.app.uysot.uz",
"authorization_endpoint": "https://app.uysot.uz/oauth-consent.html",
"token_endpoint": "https://api.service.app.uysot.uz/v1/open-api/oauth/token",
"revocation_endpoint": "https://api.service.app.uysot.uz/v1/open-api/oauth/revoke",
"registration_endpoint": "https://api.service.app.uysot.uz/v1/open-api/oauth/register",
"scopes_supported": [
"PERMISSION_OPEN_API_MCP:READ"
],
"response_types_supported": [
"code"
],
"grant_types_supported": [
"authorization_code",
"refresh_token"
],
"code_challenge_methods_supported": [
"S256"
],
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"none"
],
"revocation_endpoint_auth_methods_supported": [
"client_secret_post",
"none"
]
}