Skip to main content
POST
Authenticate
Send the pending authentication request from a thread. Open the returned hosted url to review the target and scopes, choose a supported method, and decide whether to reuse or save a matching credential. Read the thread for the verified outcome. Never put credentials in messages or tool arguments. A standalone credential setup endpoint is not public yet.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
request
string
required

The authentication request returned by the thread.

Required string length: 1 - 200
Pattern: ^[A-Za-z0-9][A-Za-z0-9_.:-]*$
Example:

"authentication-request-id"

idempotencyKey
string

A stable key for this connection attempt. Reuse it after a timeout.

Required string length: 1 - 200
Pattern: ^[A-Za-z0-9][A-Za-z0-9_.:-]*$

Response

Authorized state. Pending auth or checkout is not completion.

authentication
string
required
Required string length: 1 - 200
Pattern: ^[A-Za-z0-9][A-Za-z0-9_.:-]*$
expiresAt
string<date-time>
required
Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
status
string
required
Allowed value: "awaiting_consent"
idempotencyKey
string
Required string length: 1 - 200
Pattern: ^[A-Za-z0-9][A-Za-z0-9_.:-]*$
url
string<uri>
Maximum string length: 2048
Last modified on October 5, 2026