> ## Documentation Index
> Fetch the complete documentation index at: https://www.vitalog.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth issuer metadata

> MCP OAuth authorization with CIMD, pre-registered clients and dynamic registration; see docs/oauth.md. Enabled with a canonical public issuer. Public metadata contains no health records or credentials.



## OpenAPI

````yaml /openapi.json get /.well-known/oauth-authorization-server
openapi: 3.1.1
info:
  title: Vitalog
  version: 1.0.1
  description: >-
    Single-user structured observations with equivalent REST and MCP domain
    services. Environment AUTH_KEY or revocable personal Bearer keys with
    required name, permissions and explicit expiry (including Never); Primary
    key management requires AUTH_KEY; the UI uses separate, root-verified
    30-minute management sessions. MCP clients use OAuth authorization code with
    S256 PKCE, issued after root sign-in. Clients are resolved through HTTPS
    metadata, pre-registration or dynamic registration. OAuth tokens grant MCP
    access only.
servers:
  - url: https://vitalog-api.example.com
    description: Production REST and MCP API
  - url: http://localhost:3000
    description: Loopback development; production requires TLS ingress
security: []
paths:
  /.well-known/oauth-authorization-server:
    get:
      tags:
        - OAuth
      summary: OAuth issuer metadata
      description: >-
        MCP OAuth authorization with CIMD, pre-registered clients and dynamic
        registration; see docs/oauth.md. Enabled with a canonical public issuer.
        Public metadata contains no health records or credentials.
      operationId: oauth_issuer_metadata
      responses:
        '200':
          description: RFC 8414 authorization server metadata
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                  - issuer
                  - authorization_response_iss_parameter_supported
                  - authorization_endpoint
                  - token_endpoint
                  - registration_endpoint
                  - response_types_supported
                  - grant_types_supported
                  - client_id_metadata_document_supported
                  - token_endpoint_auth_methods_supported
                  - token_endpoint_auth_signing_alg_values_supported
                  - code_challenge_methods_supported
                  - scopes_supported
                properties:
                  issuer:
                    type: string
                    format: uri
                  authorization_response_iss_parameter_supported:
                    const: true
                  authorization_endpoint:
                    type: string
                    format: uri
                  token_endpoint:
                    type: string
                    format: uri
                  registration_endpoint:
                    type: string
                    format: uri
                  response_types_supported:
                    type: array
                    items:
                      type: string
                  grant_types_supported:
                    type: array
                    items:
                      type: string
                  client_id_metadata_document_supported:
                    const: true
                  token_endpoint_auth_methods_supported:
                    type: array
                    items:
                      type: string
                  token_endpoint_auth_signing_alg_values_supported:
                    type: array
                    items:
                      type: string
                  code_challenge_methods_supported:
                    type: array
                    items:
                      type: string
                  scopes_supported:
                    type: array
                    items:
                      type: string
      security: []

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.