Agency RollupsGet OAuth return origins

Get OAuth return origins

The origins (scheme://host[:port]) a browser may be sent back to after a GoHighLevel install or a Google destination consent, through their return_url. Empty, the default, means return_url is refused and those flows end on Mythic's own page. Airbyte OAuth keeps a separate list on PATCH /client/v1/airbyte/config.

curl -X GET "https://mythic-analytics.gulp.workers.dev/client/v1/agency/oauth-return-origins" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN"
{
  "success": true,
  "data": {
    "oauth_return_origins": [
      "https://app.agency.com"
    ]
  }
}
GET
/client/v1/agency/oauth-return-origins
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.

Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.

Responses

successboolean
dataobject