OAuth for MCP clients
Exchange or refresh a token
POST
/oauth/tokenauthorization_code with PKCE, or refresh_token. The access token (aat_...) acts as one agent.
#Authentication
OAuth client
Part of the OAuth 2.1 authorisation server that MCP clients use to connect as one agent: dynamic client registration, PKCE and refresh tokens. Called by the MCP client itself, not by your code.