---
title: Human and agent MCP OAuth
description: Authorize remote MCP through verified human Clerk sessions or AgentID identities with explicit consent and resource-bound tokens.
---

## Choose an identity

The transaction gateway implements an OAuth broker for remote MCP clients. A human signs in through Clerk, including configured Google sign-in, then reviews the client, requested resource and scope in the owner console. Explicit human consent issues `agentsub:owner` authority. An AgentID flow issues `agentsub:agent` authority; an agent cannot approve human owner scope.

The authorization UI is reached at `/app?oauth_request=<request-id>`. It offers only identities allowed by the request, and supports deliberate approval or denial. Signing in alone does not grant the requesting client access. Google owner sign-in and AgentID sign-in have been verified. The production CLI OAuth flow completed registration and the once-per-owner 100-credit ($1) grant. Production agent OAuth and the official remote MCP client handshake passed, exposing 44 tools and two resources. Agent requests to human owner controls were denied, and an API-audience token was rejected by MCP. Human API OAuth also passed. Human remote MCP OAuth also passed with the official client: 44 tools and two resources were discovered, and owner overview returned human authority, one owned agent and a 97-credit ($0.97) balance. These checks establish the tested identity flows and operations; they do not establish every provider or payment workflow.

## Discover and register

Protected HTTP MCP servers advertise RFC 9728 metadata and return a 401 Bearer challenge pointing to it. Clients discover the named authorization server through OAuth metadata or OIDC discovery. The official registration order is existing registration, advertised Client ID Metadata Documents, advertised dynamic registration, then manual client details. [MCP discovery requirements](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization/authorization-server-discovery) and [registration requirements](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization/client-registration).

AgentID currently advertises authorization-code support, S256 PKCE and dynamic registration at `/v0/register`. Its live discovery does not advertise CIMD support. Its open-client URL mechanism restricts redirects to the same HTTPS site and omits owner scopes; it must not be assumed to satisfy CIMD. Registered clients are required when owner claims or native redirects are needed. [AgentID open clients](https://www.agentid.com/docs/open-clients) and [provider reference](https://www.agentid.com/docs).

## Complete the flow

An eligible MCP client redirects for authorization, preserves state and the S256 verifier, exchanges the returned single-use code, and sends the access token on each protected request. The exact resource URI must be included in authorization and token requests: `https://api.agentsub.dev` for API access, or `https://api.agentsub.dev/mcp` / `https://mcp.agentsub.dev/mcp` for MCP. Resource servers must validate that access tokens target their resource; an OIDC ID token addressed to a login client is not automatically an MCP resource access token. [MCP authorization](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization).

Record the selected issuer and validate a returned authorization-response `iss` before exchanging the code. Keep cached client credentials bound to that issuer. AgentID advertises issuer-response support; its ten-minute tokens have no refresh token, so clients must obtain new authorization when needed.

## Integration status

The gateway publishes its own authorization server metadata, dynamic public-client registration and S256 authorization-code flow. Its broker verifies the chosen upstream identity and issues a resource-bound access token. Exact registered redirects, trusted consent origins and single-use authorization codes are enforced. Pre-registered application sign-in, AgentID token verification and a completed MCP connection remain separate checks. Client ID Metadata Documents are not advertised; public clients use the broker’s registered client flow. Public [documentation MCP](/docs/discovery) needs no OAuth.

Broker owner tokens expire after ten minutes and have no refresh token. Protected operations recheck current Clerk human identity and verified email; signing out of the browser alone does not immediately revoke a previously issued broker token.
