curl --request PUT \
--url https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"token_endpoint": "<string>",
"client_id": "<string>",
"client_secret": "<string>",
"scope": "<string>",
"resource": "<string>",
"audience": "<string>",
"organization_id": "<string>"
}
'import requests
url = "https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials"
payload = {
"token_endpoint": "<string>",
"client_id": "<string>",
"client_secret": "<string>",
"scope": "<string>",
"resource": "<string>",
"audience": "<string>",
"organization_id": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
token_endpoint: '<string>',
client_id: '<string>',
client_secret: '<string>',
scope: '<string>',
resource: '<string>',
audience: '<string>',
organization_id: '<string>'
})
};
fetch('https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'token_endpoint' => '<string>',
'client_id' => '<string>',
'client_secret' => '<string>',
'scope' => '<string>',
'resource' => '<string>',
'audience' => '<string>',
'organization_id' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials"
payload := strings.NewReader("{\n \"token_endpoint\": \"<string>\",\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"scope\": \"<string>\",\n \"resource\": \"<string>\",\n \"audience\": \"<string>\",\n \"organization_id\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"token_endpoint\": \"<string>\",\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"scope\": \"<string>\",\n \"resource\": \"<string>\",\n \"audience\": \"<string>\",\n \"organization_id\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"token_endpoint\": \"<string>\",\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"scope\": \"<string>\",\n \"resource\": \"<string>\",\n \"audience\": \"<string>\",\n \"organization_id\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"connected": true,
"has_auth": true,
"agent_context_id": "<string>",
"auth_type": "oauth_client_credentials"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Save OAuth 2.0 client-credentials for an agent
Store a machine-to-machine OAuth 2.0 client-credentials configuration (RFC 6749 §4.4) for this agent. The SDK exchanges at the token endpoint before every call and refreshes on 401. client_secret may be a $ENV:VAR_NAME reference — the SDK resolves at exchange time, the server stores it as written (encrypted uniformly). Requires authentication and ownership.
curl --request PUT \
--url https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"token_endpoint": "<string>",
"client_id": "<string>",
"client_secret": "<string>",
"scope": "<string>",
"resource": "<string>",
"audience": "<string>",
"organization_id": "<string>"
}
'import requests
url = "https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials"
payload = {
"token_endpoint": "<string>",
"client_id": "<string>",
"client_secret": "<string>",
"scope": "<string>",
"resource": "<string>",
"audience": "<string>",
"organization_id": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
token_endpoint: '<string>',
client_id: '<string>',
client_secret: '<string>',
scope: '<string>',
resource: '<string>',
audience: '<string>',
organization_id: '<string>'
})
};
fetch('https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'token_endpoint' => '<string>',
'client_id' => '<string>',
'client_secret' => '<string>',
'scope' => '<string>',
'resource' => '<string>',
'audience' => '<string>',
'organization_id' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials"
payload := strings.NewReader("{\n \"token_endpoint\": \"<string>\",\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"scope\": \"<string>\",\n \"resource\": \"<string>\",\n \"audience\": \"<string>\",\n \"organization_id\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"token_endpoint\": \"<string>\",\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"scope\": \"<string>\",\n \"resource\": \"<string>\",\n \"audience\": \"<string>\",\n \"organization_id\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://agenticadvertising.org/api/registry/agents/{encodedUrl}/oauth-client-credentials")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"token_endpoint\": \"<string>\",\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"scope\": \"<string>\",\n \"resource\": \"<string>\",\n \"audience\": \"<string>\",\n \"organization_id\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"connected": true,
"has_auth": true,
"agent_context_id": "<string>",
"auth_type": "oauth_client_credentials"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Authorizations
Bearer token in the Authorization header. Two token types are accepted:
- Organization API key (
sk_...) issued via the dashboard. Org-scoped, long-lived, for server-to-server use. - User JWT obtained via the OAuth 2.1 authorization code flow with PKCE. User-scoped, short-lived. Discover the authorization server at
/.well-known/oauth-authorization-serverand the protected-resource metadata at/.well-known/oauth-protected-resource/api.
Path Parameters
URL-encoded agent URL
Body
Token endpoint URL (HTTPS required; localhost allowed in dev).
2048OAuth client ID. May be a $ENV:VAR_NAME reference.
2048OAuth client secret. May be a $ENV:VAR_NAME reference. Stored encrypted at rest.
8192Space-separated OAuth scope values.
1024RFC 8707 resource indicator. Accepts a single URI string or an array of 1–8 URI strings for multi-resource authorization servers (Keycloak strict, AWS Cognito multi-RS).
2048Audience parameter for audience-validating authorization servers.
2048Client-credentials placement: basic (HTTP Basic header, RFC 6749 §2.3.1 preferred) or body (form fields). SDK default is basic.
basic, body Selected organization ID. The caller must own the agent in this organization.
Was this page helpful?