Developers

HTTP endpoints

Every public endpoint a developer calls, all on https://production-engine.com. Workspace data is read through the MCP server; the rest is OAuth.

Summary

Method and pathAuthPurpose
POST /api/mcpBearer tokenMCP server
GET /.well-known/oauth-protected-resource/api/mcpNoneProtected-resource metadata (RFC 9728)
GET /.well-known/oauth-protected-resourceNoneThe same document
GET /.well-known/oauth-authorization-serverNoneAuthorization-server metadata (RFC 8414)
POST /api/oauth/registerNoneDynamic client registration
GET /oauth/authorizeSigns the person inApproval page
POST /api/oauth/tokenPKCE or refresh tokenToken endpoint

Records are also read through the REST API at /api/v1. Everything else under /api serves the Production Engine app itself, is tied to a signed-in browser session, and can change without notice. Do not build on it.

POST /api/mcp

One JSON-RPC 2.0 message per request, up to 256 KB, answered with JSON. GET and DELETE return 405. A request without a valid token gets a 401 with a WWW-Authenticate challenge. Full reference: MCP server.

Discovery documents

Both documents are public JSON, sent with Access-Control-Allow-Origin: * and Cache-Control: no-store, so a browser-based client can read them.

GET /.well-known/oauth-protected-resource/api/mcp
{
  "resource": "https://production-engine.com/api/mcp",
  "authorization_servers": [
    "https://production-engine.com"
  ],
  "scopes_supported": [
    "read",
    "estimate"
  ],
  "bearer_methods_supported": [
    "header"
  ],
  "resource_name": "Production Engine"
}
GET /.well-known/oauth-authorization-server
{
  "issuer": "https://production-engine.com",
  "authorization_endpoint": "https://production-engine.com/oauth/authorize",
  "token_endpoint": "https://production-engine.com/api/oauth/token",
  "registration_endpoint": "https://production-engine.com/api/oauth/register",
  "scopes_supported": [
    "read",
    "estimate"
  ],
  "response_types_supported": [
    "code"
  ],
  "response_modes_supported": [
    "query"
  ],
  "grant_types_supported": [
    "authorization_code",
    "refresh_token"
  ],
  "code_challenge_methods_supported": [
    "S256"
  ],
  "token_endpoint_auth_methods_supported": [
    "none"
  ],
  "authorization_response_iss_parameter_supported": true
}

OAuth endpoints

EndpointBodySuccess
POST /api/oauth/registerJSON, up to 16 KB201 with the client record
POST /api/oauth/tokenForm-encoded or JSON, up to 16 KB200 with a token pair

Both answer CORS preflight requests and send Access-Control-Allow-Origin: *, so they can be called from a browser. Errors use the OAuth shape { "error": "...", "error_description": "..." }. Request fields and examples are on the Authentication page; error codes and rate limits are on Errors and limits.