> ## Documentation Index
> Fetch the complete documentation index at: https://www.vitalog.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth authorize

> MCP OAuth authorization with CIMD, pre-registered clients and dynamic registration; see docs/oauth.md. Enabled with a canonical public issuer. Public metadata contains no health records or credentials.



## OpenAPI

````yaml /openapi.json get /oauth/authorize
openapi: 3.1.1
info:
  title: Vitalog
  version: 1.0.1
  description: >-
    Single-user structured observations with equivalent REST and MCP domain
    services. Environment AUTH_KEY or revocable personal Bearer keys with
    required name, permissions and explicit expiry (including Never); Primary
    key management requires AUTH_KEY; the UI uses separate, root-verified
    30-minute management sessions. MCP clients use OAuth authorization code with
    S256 PKCE, issued after root sign-in. Clients are resolved through HTTPS
    metadata, pre-registration or dynamic registration. OAuth tokens grant MCP
    access only.
servers:
  - url: https://vitalog-api.example.com
    description: Production REST and MCP API
  - url: http://localhost:3000
    description: Loopback development; production requires TLS ingress
security: []
paths:
  /oauth/authorize:
    get:
      tags:
        - OAuth
      summary: OAuth authorize
      description: >-
        MCP OAuth authorization with CIMD, pre-registered clients and dynamic
        registration; see docs/oauth.md. Enabled with a canonical public issuer.
        Public metadata contains no health records or credentials.
      operationId: oauth_authorize
      parameters:
        - name: response_type
          in: query
          required: true
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            const: code
        - name: client_id
          in: query
          required: true
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            minLength: 1
            maxLength: 512
            pattern: ^[^\s\u0000-\u001f\u007f]+$
        - name: redirect_uri
          in: query
          required: true
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            minLength: 1
            maxLength: 512
            pattern: ^[^\s\u0000-\u001f\u007f]+$
        - name: resource
          in: query
          required: true
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            maxLength: 512
        - name: code_challenge
          in: query
          required: true
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            pattern: ^[A-Za-z0-9_-]{43}$
        - name: code_challenge_method
          in: query
          required: true
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            const: S256
        - name: state
          in: query
          required: false
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            maxLength: 512
        - name: scope
          in: query
          required: false
          schema:
            $schema: https://json-schema.org/draft/2020-12/schema
            type: string
            maxLength: 128
      responses:
        '302':
          description: >-
            Resolve the client through configuration, persistent registration or
            its HTTPS metadata document. Validate the requested callback before
            redirecting. A valid request establishes a signed HttpOnly API-host
            flow cookie and opens the separate Next.js consent screen. Errors
            return only to a validated callback with issuer and the supplied
            state. Unknown clients and unregistered callbacks stay local. S256
            PKCE is required; unknown OAuth parameters are ignored.
          headers:
            Location:
              schema:
                type: string
                format: uri
        '400':
          description: OAuth protocol error
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                  - error
                  - error_description
                properties:
                  error:
                    type: string
                  error_description:
                    type: string
      security: []

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.