> ## Documentation Index
> Fetch the complete documentation index at: https://docs.duvo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authorize MCP OAuth

> Start an OAuth-based connection with a remote MCP server using Dynamic Client Registration. Returns an authorization URL the user must open in a browser; once they grant consent, Duvo creates the matching connection and redirects the browser to the optional `returnUrl`.



## OpenAPI

````yaml /api-reference/openapi.json post /v2/teams/{teamId}/connections/oauth/mcp/start
openapi: 3.0.3
info:
  title: Duvo Public API
  description: >-
    Public API for programmatic access to Duvo. Authenticate with API keys
    created in the Duvo dashboard.
  version: 1.0.0
servers:
  - url: https://api.duvo.ai
    description: Production server
security: []
tags:
  - name: Runs
    description: Start, monitor, and manage agent runs (Runs in the Duvo UI)
  - name: Sandboxes
    description: Create sandboxes and upload files for agent runs
  - name: Queues
    description: Manage queues and their agent bindings
  - name: Cases
    description: Create, list, and manage cases and their labels within queues
  - name: Case Approvals
    description: Submit decisions on pending case approval requests issued by an agent run
  - name: Agents
    description: Create and manage agents for automation workloads
  - name: Revisions
    description: Create and manage agent revisions — the underlying Setup for an Agent
  - name: Agent Folders
    description: Organize agents into folders
  - name: Agent Memory
    description: Read an agent's memory files (the Memory feature in the Duvo UI)
  - name: Suggestions
    description: >-
      List, apply, and dismiss an Agent's improvement suggestions (the
      suggestions inbox in the Duvo UI)
  - name: Schedules
    description: List schedules configured for an agent
  - name: Duvo Pulse
    description: >-
      Create, list, iterate on, and delete Duvo Pulse dashboards — live,
      agent-generated visualizations of your Duvo data
  - name: Case Triggers
    description: >-
      Configure case triggers that automatically dispatch agent runs (Runs in
      the Duvo UI) for cases added to a queue
  - name: Triggers
    description: >-
      Configure event triggers that start a Run automatically when an external
      event fires (e.g. an email arrives, a Linear issue is created, or a file
      changes in Google Drive)
  - name: Skills
    description: Manage team and system skills (reusable knowledge packs).
  - name: Files
    description: Manage team files.
  - name: Plugins
    description: Discover plugins that can be referenced from a revision.
  - name: Organizations
    description: Inspect organizations you belong to and the teams within them
  - name: Team
    description: Inspect the team and members associated with the API key
  - name: Integrations
    description: Browse the team's catalog of available integration types
  - name: Connections
    description: Manage your connected integrations
  - name: Credentials
    description: >-
      Manage logins (domain + username + password + TOTP) used by agents to sign
      in to websites and desktop applications, and attach them to assignment
      revisions
  - name: Secrets
    description: >-
      Manage env-var secrets injected into runs, and attach them to assignment
      revisions. Only metadata is exposed; values are never returned
  - name: Revision Integrations
    description: >-
      Attach integrations to assignment revisions, pin specific connections, and
      link queues
  - name: ClarityV2
    description: >-
      Manage Clarity v2 process snapshots, transformation proposals, and the
      extra-capture-request follow-up loop
paths:
  /v2/teams/{teamId}/connections/oauth/mcp/start:
    post:
      tags:
        - Connections
      summary: Authorize MCP OAuth
      description: >-
        Start an OAuth-based connection with a remote MCP server using Dynamic
        Client Registration. Returns an authorization URL the user must open in
        a browser; once they grant consent, Duvo creates the matching connection
        and redirects the browser to the optional `returnUrl`.
      operationId: authorizeMcpOAuth
      parameters:
        - name: teamId
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                mcp_server_url:
                  type: string
                  format: uri
                  description: URL of the MCP server requiring OAuth.
                name:
                  type: string
                  minLength: 1
                  description: Human-readable name to display for the connection.
                custom_integration_id:
                  description: >-
                    Optional ID of a custom integration this connection should
                    be associated with.
                  type: string
                  format: uuid
                return_url:
                  description: >-
                    Where to send the user's browser after consent completes.
                    Accepts an absolute URL on a domain Duvo allows, or a path
                    relative to the Duvo frontend (e.g. `/integrations/slack`).
                  type: string
                integration_type:
                  description: >-
                    Optional catalog integration type (e.g. `netsuite`,
                    `asana`). When it names a known MCP OAuth catalog
                    integration and `mcp_server_url` matches that integration's
                    registered server, the connection is treated as a catalog
                    connection; otherwise it requires the custom MCP servers
                    capability.
                  type: string
                reconnect_instance_id:
                  description: >-
                    When set, the OAuth flow will update the existing connection
                    in place rather than creating a new one.
                  type: string
                  format: uuid
                oauth_client_id:
                  description: >-
                    OAuth client ID of a client the user registered on the
                    authorization server themselves (e.g. a NetSuite Integration
                    record). Takes precedence over preregistered credentials and
                    Dynamic Client Registration. Cannot be combined with
                    custom_integration_id. On reconnect, omit to reuse the
                    connection's stored credentials, or provide to replace
                    (rotate) them.
                  type: string
                  minLength: 1
                oauth_client_secret:
                  description: >-
                    Client secret for `oauth_client_id`. Omit for public clients
                    (PKCE-only).
                  type: string
                  minLength: 1
              required:
                - mcp_server_url
                - name
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  authorization_url:
                    type: string
                    description: OAuth provider authorization URL to open in a browser
                required:
                  - authorization_url
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
                additionalProperties: false
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key authentication. Get your API key from the Duvo dashboard.

````