Skip to content
agentsub
Esc
↑↓navigate↵open⌘Jpreview

Renew an AgentID social identity through the registered direct broker

Exact trusted browser Origin and current signed Clerk session are required. Backend verifies active SID, user, and exactly one actual AgentID external account. No client-supplied owner, subject, email or return URL is accepted. A five-minute server PKCE/nonce session binds the actual providerUserId. Callback verifies signed ID token plus fresh authenticated userinfo and exact subject agreement, rechecks the active Clerk session/account, writes only a private 24-hour immutable-provenance social binding, and redirects fixed https://agentsub.dev/app. It creates no client grant or credits. Normal subsequent authenticated registration separately enforces owner binding and once-owner welcome credits.

POST/oauth/social/connect
Authorization
AuthorizationBearer token (JWT) · headerrequired

Backend-verified Clerk AgentID social session, own-agent read/service actions only

Request body
requiredapplication/json
object
Responses
200

Actual registered AgentID authorization URL

redirectUrlstring<uri>required
400

OAuth error JSON (invalid_request, invalid_client, invalid_grant, invalid_scope, invalid_target, invalid_redirect_uri, invalid_client_metadata, unsupported_grant_type)

errorstringrequired
Allowed:invalid_requestinvalid_clientinvalid_grantinvalid_scopeinvalid_targetinvalid_redirect_uriinvalid_client_metadataunsupported_grant_typeaccess_deniedtemporarily_unavailable
error_descriptionstringrequired
403

Untrusted origin, inactive Clerk session, wrong external account, or subject mismatch

503

OAuth error JSON (temporarily_unavailable — credentials or storage not configured)

errorstringrequired
Allowed:invalid_requestinvalid_clientinvalid_grantinvalid_scopeinvalid_targetinvalid_redirect_uriinvalid_client_metadataunsupported_grant_typeaccess_deniedtemporarily_unavailable
error_descriptionstringrequired
Request
curl -X POST 'https://api.agentsub.dev/oauth/social/connect' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
Response
{
  "redirectUrl": "http://example.com"
}