Agency RollupsReplace OAuth return origins

Replace OAuth return origins

Replace the whole list. Each entry is reduced to its origin, so a path or query is dropped, and duplicates are removed. At most 20 entries, http or https only, no credentials. A scoped mcp_ key needs agency:write.

curl -X PUT "https://mythic-analytics.gulp.workers.dev/client/v1/agency/oauth-return-origins" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -d '{
  "oauth_return_origins": [
    "https://app.agency.com",
    "http://localhost:8080"
  ]
}'
{
  "success": true,
  "data": {
    "oauth_return_origins": [
      "https://app.agency.com"
    ]
  }
}
PUT
/client/v1/agency/oauth-return-origins
PUT
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.

Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.
Content-Typestring
Required

The media type of the request body

Options: application/json
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Agency key (ak_) only — a location secret key (sk_) gets 403 agency_required. Keys are server-side credentials; this surface serves no CORS headers on purpose. Agency-wide scoped keys (mcp_ with no fixed location) are accepted too and need agency:read; a client-bound mcp_ key gets 403 agency_key_required. See Using an mcp_ key over HTTP.

Body

application/json
oauth_return_originsarray
Required
Example:
["https://app.agency.com","http://localhost:8080"]

Responses

successboolean
dataobject