Developers
HTTP endpoints
Every public endpoint a developer calls, all on https://production-engine.com. Workspace data is read through the MCP server; the rest is OAuth.
Summary
| Method and path | Auth | Purpose |
|---|---|---|
POST /api/mcp | Bearer token | MCP server |
GET /.well-known/oauth-protected-resource/api/mcp | None | Protected-resource metadata (RFC 9728) |
GET /.well-known/oauth-protected-resource | None | The same document |
GET /.well-known/oauth-authorization-server | None | Authorization-server metadata (RFC 8414) |
POST /api/oauth/register | None | Dynamic client registration |
GET /oauth/authorize | Signs the person in | Approval page |
POST /api/oauth/token | PKCE or refresh token | Token endpoint |
Records are also read through the REST API at /api/v1. Everything else under /api serves the Production Engine app itself, is tied to a signed-in browser session, and can change without notice. Do not build on it.
POST /api/mcp
One JSON-RPC 2.0 message per request, up to 256 KB, answered with JSON. GET and DELETE return 405. A request without a valid token gets a 401 with a WWW-Authenticate challenge. Full reference: MCP server.
Discovery documents
Both documents are public JSON, sent with Access-Control-Allow-Origin: * and Cache-Control: no-store, so a browser-based client can read them.
{
"resource": "https://production-engine.com/api/mcp",
"authorization_servers": [
"https://production-engine.com"
],
"scopes_supported": [
"read",
"estimate"
],
"bearer_methods_supported": [
"header"
],
"resource_name": "Production Engine"
}{
"issuer": "https://production-engine.com",
"authorization_endpoint": "https://production-engine.com/oauth/authorize",
"token_endpoint": "https://production-engine.com/api/oauth/token",
"registration_endpoint": "https://production-engine.com/api/oauth/register",
"scopes_supported": [
"read",
"estimate"
],
"response_types_supported": [
"code"
],
"response_modes_supported": [
"query"
],
"grant_types_supported": [
"authorization_code",
"refresh_token"
],
"code_challenge_methods_supported": [
"S256"
],
"token_endpoint_auth_methods_supported": [
"none"
],
"authorization_response_iss_parameter_supported": true
}OAuth endpoints
| Endpoint | Body | Success |
|---|---|---|
POST /api/oauth/register | JSON, up to 16 KB | 201 with the client record |
POST /api/oauth/token | Form-encoded or JSON, up to 16 KB | 200 with a token pair |
Both answer CORS preflight requests and send Access-Control-Allow-Origin: *, so they can be called from a browser. Errors use the OAuth shape { "error": "...", "error_description": "..." }. Request fields and examples are on the Authentication page; error codes and rate limits are on Errors and limits.