---
search:
  tags:
    - OAuth
    - GET
seo:
  description: >-
    Exchanges the upstream AgentID code, verifies the ID token (AgentID iss,
    ES256)… Reference for the GET /oauth/callback endpoint in the agentsub
    Gateway API.
sidebar:
  label: AgentID authorization callback
  badge: GET
title: AgentID authorization callback
type: openapi-operation
---
Exchanges the upstream AgentID code, verifies the ID token (AgentID iss, ES256) including `nonce`, `actor_type=agent` and verified `owner_email` claims, then 302-redirects to the client's registered redirect URI with `code`, `state` and `iss=https://api.agentsub.dev`. Codes are single-use and valid for 60 seconds.

`GET /oauth/callback`

**Responses**

- `302` — Redirect to the registered client redirect URI
- `400` — OAuth error JSON (\`invalid\_request\`, \`invalid\_client\`, \`invalid\_grant\`, \`invalid\_scope\`, \`invalid\_target\`, \`invalid\_redirect\_uri\`, \`invalid\_client\_metadata\`, \`unsupported\_grant\_type\`)
- `403` — OAuth error JSON (\`access\_denied\` — missing verified owner claims or nonce)
- `503` — OAuth error JSON (\`temporarily\_unavailable\` — credentials or storage not configured)
