YouBothAgent▾
You — Business rules and flows you own. Read these yourself.
Both — Know the idea; your agent follows the details.
Agent — Conventions and references your agent follows. Look up as needed.
/oauth/revoke answers 200 whether or not the token was live, so it cannot double as a token oracle.AKAN_MCP_SCOPES is for tokens another issuer mints; set on an app that runs this server, it refuses every token the server issues./mcp answers 401 and points the client at its metadata. With one, the token rides the Authorization header:/mcp deletes the cookie header before the account middleware runs. Otherwise a same-site page could drive tools/call on a visitor's session, and this route never passes through CrossSiteGuard.aud, no entry. Once an issuer is named it mints tokens for its other resources too, so a token with no audience is the confused-deputy case RFC 8707 exists for. A token issued for another resource is refused as well.accessTokenSeconds, an hour by default. The refresh token rotates on every use and lasts thirty days.JWT_SECRET is required outside local. Set it, or security.jwtSecret, in every deployment. Without either, the secret would be derived from the app name, the environment and the repo name, three strings anyone can read off a URL, and every token on this page would be forgeable, admin sessions included.allowedRedirectSchemes names the scheme, then matched exactly.localhost counts as loopback. RFC 8252 discourages it, but Claude Code redirects there.cursor is the default scheme. Cursor's desktop client registers cursor://…/oauth/callback, and a server that refuses it cannot be used from Cursor at all.#fragment is refused at registration.redirectUris come from your own config, so only the exact match applies, with the same loopback port exception.code_challenge_method is refused even when the challenge itself is well formed.aud; set it if MCP moved off /mcp./office/oauth/consent.?redirect= back to consent; basePath included.client_id as a metadata document; off also stops advertising it.http://localhost:<port> in local, and https://<host> elsewhere, where the host is HOST_NAME, then hostname, then <app>-<environment>.<serveDomain>./office writes /office/oauth/consent and /office/signin.koyo:// above needs no allowedRedirectSchemes entry. A static client's redirectUris skip the scheme check; the option only widens what dynamic and metadata-document clients may register.refusePrivateAddresses off only behind an egress policy. Unless the network already closes the private range, a client_id URL can aim the server at its own network.clients is an OAuthStaticClient:client_id this client presents.none.Every, kept off MCP. Both are mcp: false: an agent that could list and cut every other connector from inside a tool call is exactly the lever a connected-apps page exists to keep human.sid each token carries, is denylisted for accessTokenSeconds.Person makes the act absent, not hidden. It declares static agents = false, so the MCP catalogue refuses every endpoint it guards instead of hiding it per caller.AgentCall narrows the side effects, not the endpoint. The endpoint stays callable and listed; what changes is what the call sets in motion: no customer mail, no push, no irreversible side effect.isAgentCall(context). Both levers call it from @libs/shared/srvkit: context.origin === "mcp", or a token naming a client_id or an aud. Never sniff those claims through a cast; an absent one means different things on different transports, and a hand-rolled check drifts from the answer the guards give.