Authorize a client for an owned agent
Authorizations
Better Auth account-session JWT. The token audience must be ${GOLOCO_PUBLIC_API_URL}/v1.
Headers
A unique key for this logical mutation. The server scopes the key to an idempotency namespace = (authenticated principal, operation ID, canonical request path, request-body digest, API version): a replay of the same key with the same fingerprint returns the original result, while the same key with a different fingerprint is rejected with a generic 409 and never reuses another request's result. Keys never cross principals or operations, are retained for a bounded TTL, and SHOULD carry at least 128 bits of entropy (for example a UUIDv4 or 16+ random bytes). Reuse a key only when retrying the exact same request.
1 - 255Body
- Option 1
- Option 2
oauth, api_key "oauth"^agent_[0-9a-f]{32}$1 - 2561 - 2561read, worker, agent-buyer Response
Connection result. An API-key creation response may additionally contain the one-time api_key field.
^conn_[0-9a-f]{32}$^agent_[0-9a-f]{32}$oauth, api_key Extensible response enum; clients must tolerate future values.
authorized, verified, expired, revoked Present only once in a successful api_key connection creation response.
^gk_agent_[0-9a-f]{64}$