Authorization
- OAuth 2.1 authorization code flow with PKCE.
code_challenge_method=S256is required, and so isstate. - Public clients only:
token_endpoint_auth_methodisnone. Sendclient_idin the form body; a BasicAuthorizationheader or aclient_secretis refused withinvalid_request. resource=https://mcp.nanocorp.so(RFC 8707). A trailing slash is accepted. When it is absent or empty, the request is bound to the MCP server.scope=nanocorp, which grants the user’s full access.openidandoffline_accessare accepted and ignored.- No
nonceis needed and no ID token is issued. - Every redirect back to the client carries
iss(RFC 9207). prompt=nonereturns a code when the user’s consent is current. Otherwise a pre-registered client getslogin_requiredorconsent_required. Any otherpromptvalue, andmax_age, is refused withinvalid_request.response_modemust bequerywhen sent.- Until a user has approved your redirect URI, an authorization error for a
self-registered client (
prompt=noneincluded) is shown to the user on a NanoCorp page instead of being redirected to you. - Redirect URIs are compared exactly, except the port of a native client’s
httploopback redirect.
Client registration
Use one of three ways:-
Client ID metadata document. Your
client_idis thehttpsURL of a JSON document you publish, with a path and no query or fragment. The document’sclient_idmust equal that URL exactly, and it needsclient_nameandredirect_uris. When it liststoken_endpoint_auth_methods_supported, the list must includenone; without that list,token_endpoint_auth_methodmust benoneor absent. Serve it from a public address, asapplication/json, without redirects, within 10 seconds and 64 KB. It is cached for up to 24 hours (max-ageis honored). The confirmation page shows its host as the source of the app details. -
Dynamic client registration (RFC 7591) at
POST https://accounts.nanocorp.so/oidc/register:redirect_uris: 1 to 10 entries.webclients (the defaultapplication_type) usehttpsonly;nativeclients may also usehttpon127.0.0.1,[::1]orlocalhost, with any port and path.grant_types: absent, or a list that includesauthorization_code. Other grants you list are ignored: the registration is stored asauthorization_codeonly.response_types: absent or["code"].token_endpoint_auth_method: absent ornone.client_name: required, 1 to 64 characters.client_uri: optional,https.logo_uriand unknown fields are ignored.
201with yourclient_id,client_id_issued_atand the accepted metadata. No secret is issued. -
Pre-registered client. Write to
support@nanocorp.so if you need a fixed
client ID. The confirmation page then shows your name as
Registered with NanoCorp. Meta Muse uses the pre-registered client ID
nca_ed8095a90ede567a36e12ca1.
Tokens and revocation
Exchange the code atPOST https://accounts.nanocorp.so/oidc/token with
grant_type=authorization_code, code, redirect_uri, client_id and
code_verifier. The response is:
POST https://accounts.nanocorp.so/oidc/revoke, form-encoded, with token
and client_id (RFC 7009). A well-formed request always gets 200, whether
or not the token was live. A revoked token stops working within a minute.