---
search:
  tags:
    - OAuth
    - POST
seo:
  description: >-
    Exact trusted browser Origin and current signed Clerk session are… Reference
    for the POST /oauth/social/connect endpoint in the agentsub Gateway API.
sidebar:
  label: Renew an AgentID social identity through the registered direct broker
  badge: POST
title: Renew an AgentID social identity through the registered direct broker
type: openapi-operation
---
Exact trusted browser Origin and current signed Clerk session are required. Backend verifies active SID, user, and exactly one actual AgentID external account. No client-supplied owner, subject, email or return URL is accepted. A five-minute server PKCE/nonce session binds the actual providerUserId. Callback verifies signed ID token plus fresh authenticated userinfo and exact subject agreement, rechecks the active Clerk session/account, writes only a private 24-hour immutable-provenance social binding, and redirects fixed https://agentsub.dev/app. It creates no client grant or credits. Normal subsequent authenticated registration separately enforces owner binding and once-owner welcome credits.

`POST /oauth/social/connect`

**Request body** (`application/json`, required)

Request body example:

```json
{}
```

**Responses**

- `200` — Actual registered AgentID authorization URL
- `400` — OAuth error JSON (\`invalid\_request\`, \`invalid\_client\`, \`invalid\_grant\`, \`invalid\_scope\`, \`invalid\_target\`, \`invalid\_redirect\_uri\`, \`invalid\_client\_metadata\`, \`unsupported\_grant\_type\`)
- `403` — Untrusted origin, inactive Clerk session, wrong external account, or subject mismatch
- `503` — OAuth error JSON (\`temporarily\_unavailable\` — credentials or storage not configured)

Response example, 200:

```json
{
  "redirectUrl": "http://example.com"
}
```
