> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nanocorp.so/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> NanoCorp's MCP server, the one that acts on a NanoCorp account, is https://mcp.nanocorp.so (OAuth sign-in).
> This documentation site's /mcp endpoint and its /.well-known/mcp files are a documentation search server, not NanoCorp.
> To connect an AI agent to NanoCorp, follow https://docs.nanocorp.so/agents.

# Sign-in (OAuth)

> How a client signs a NanoCorp user in: authorization, client registration, tokens and revocation.

## Authorization

* OAuth 2.1 authorization code flow with PKCE. `code_challenge_method=S256` is
  required, and so is `state`.
* Public clients only: `token_endpoint_auth_method` is `none`. Send
  `client_id` in the form body; a Basic `Authorization` header or a
  `client_secret` is refused with `invalid_request`.
* `resource=https://mcp.nanocorp.so` (RFC 8707). A trailing slash is
  accepted. When it is absent or empty, the request is bound to the MCP
  server.
* `scope=nanocorp`, which grants the user's full access. `openid` and
  `offline_access` are accepted and ignored.
* No `nonce` is needed and no ID token is issued.
* Every redirect back to the client carries `iss` (RFC 9207).
* `prompt=none` returns a code when the user's consent is current. Otherwise a
  pre-registered client gets `login_required` or `consent_required`. Any other
  `prompt` value, and `max_age`, is refused with `invalid_request`.
  `response_mode` must be `query` when sent.
* Until a user has approved your redirect URI, an authorization error for a
  self-registered client (`prompt=none` included) is shown to the user on a
  NanoCorp page instead of being redirected to you.
* Redirect URIs are compared exactly, except the port of a native client's
  `http` loopback redirect.

Consent is remembered per user and client, for the redirect URI the user last
approved. It is asked again for another redirect URI, a changed list of
redirect URIs, a new registration, or when NanoCorp updates its consent page.

## Client registration

Use one of three ways:

1. **Client ID metadata document.** Your `client_id` is the `https` URL of a
   JSON document you publish, with a path and no query or fragment. The
   document's `client_id` must equal that URL exactly, and it needs
   `client_name` and `redirect_uris`. When it lists
   `token_endpoint_auth_methods_supported`, the list must include `none`;
   without that list, `token_endpoint_auth_method` must be `none` or absent. Serve
   it from a public address, as `application/json`, without redirects, within
   10 seconds and 64 KB. It is cached for up to 24 hours (`max-age` is
   honored). The confirmation page shows its host as the source of the app
   details.
2. **Dynamic client registration** (RFC 7591) at
   `POST https://accounts.nanocorp.so/oidc/register`:

   * `redirect_uris`: 1 to 10 entries. `web` clients (the default
     `application_type`) use `https` only; `native` clients may also use
     `http` on `127.0.0.1`, `[::1]` or `localhost`, with any port and path.
   * `grant_types`: absent, or a list that includes `authorization_code`.
     Other grants you list are ignored: the registration is stored as
     `authorization_code` only.
   * `response_types`: absent or `["code"]`. `token_endpoint_auth_method`:
     absent or `none`.
   * `client_name`: required, 1 to 64 characters. `client_uri`: optional,
     `https`. `logo_uri` and unknown fields are ignored.

   The response is `201` with your `client_id`, `client_id_issued_at` and the
   accepted metadata. No secret is issued.
3. **Pre-registered client.** Write to
   [support@nanocorp.so](mailto:support@nanocorp.so) if you need a fixed
   client ID. The confirmation page then shows your name as
   **Registered with NanoCorp**. Meta Muse uses the pre-registered client ID
   `nca_ed8095a90ede567a36e12ca1`.

## Tokens and revocation

Exchange the code at `POST https://accounts.nanocorp.so/oidc/token` with
`grant_type=authorization_code`, `code`, `redirect_uri`, `client_id` and
`code_verifier`. The response is:

```json theme={null}
{ "access_token": "...", "token_type": "Bearer", "scope": "nanocorp" }
```

The access token is opaque and does not expire. There is no refresh token.
It works on the MCP endpoint only. A user keeps at most 100 live tokens per
client: the 101st revokes the oldest.

Revoke a token when the user disconnects:
`POST https://accounts.nanocorp.so/oidc/revoke`, form-encoded, with `token`
and `client_id` (RFC 7009). A well-formed request always gets `200`, whether
or not the token was live. A revoked token stops working within a minute.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.