> ## Documentation Index
> Fetch the complete documentation index at: https://www.vitalog.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth connection request

> MCP OAuth authorization with CIMD, pre-registered clients and dynamic registration; see docs/oauth.md. Enabled with a canonical public issuer. Public metadata contains no health records or credentials.



## OpenAPI

````yaml /openapi.json get /oauth/request
openapi: 3.1.1
info:
  title: Vitalog
  version: 1.0.2
  description: >-
    Single-user structured observations with equivalent REST and MCP domain
    services. Environment AUTH_KEY or revocable personal Bearer keys with
    required name, permissions and explicit expiry (including Never); Primary
    key management requires AUTH_KEY; the UI uses separate, root-verified
    30-minute management sessions. MCP clients use OAuth authorization code with
    S256 PKCE, issued after root sign-in. Clients are resolved through HTTPS
    metadata, pre-registration or dynamic registration. OAuth tokens grant MCP
    access only.
servers:
  - url: https://vitalog-api.example.com
    description: Production REST and MCP API
  - url: http://localhost:3000
    description: Loopback development; production requires TLS ingress
security: []
paths:
  /oauth/request:
    get:
      tags:
        - OAuth
      summary: OAuth connection request
      description: >-
        MCP OAuth authorization with CIMD, pre-registered clients and dynamic
        registration; see docs/oauth.md. Enabled with a canonical public issuer.
        Public metadata contains no health records or credentials.
      operationId: oauth_connection_request
      responses:
        '200':
          description: Private consent request and CSRF token
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                  - client_id
                  - client_name
                  - redirect_uri
                  - scopes
                  - csrf_token
                properties:
                  client_id:
                    type: string
                    maxLength: 512
                  client_name:
                    type: string
                    minLength: 1
                    maxLength: 100
                  redirect_uri:
                    type: string
                    format: uri
                  scopes:
                    type: array
                    items:
                      type: string
                  csrf_token:
                    type: string
                    pattern: ^[A-Za-z0-9_-]{43}$
        '400':
          description: OAuth protocol error
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                  - error
                  - error_description
                properties:
                  error:
                    type: string
                  error_description:
                    type: string
      security:
        - oauthFlowCookie: []
components:
  securitySchemes:
    oauthFlowCookie:
      type: apiKey
      in: cookie
      name: __Secure-vitalog-oauth
      description: >-
        Signed HttpOnly consent-flow cookie from /oauth/authorize, valid for
        five minutes. Loopback development uses vitalog-oauth.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.