> ## Documentation Index
> Fetch the complete documentation index at: https://docs.runaether.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Save the organization's OAuth app for an issuer

> Org admins only. Stores the client id and secret of the OAuth app the organization registered at the issuer's authorization server. Re-entering the secret with the app's client id rotates it, and the connections made with the app stay; another client id replaces the app, and every connection made with the replaced one needs its owner to connect again (needs_reauth, revoked). The issuer's metadata is read first: the app is stored for the issuer it names, and Aether sends the secret to its token endpoint by client_secret_basic or client_secret_post as its token_endpoint_auth_methods_supported allows (mcp_oauth_app_auth_method_unsupported when it allows neither). Every server of the issuer in the organization then connects with the app, members' own connections and the organization's alike, unless the issuer offers Aether a client ID metadata document or dynamic client registration. The secret is encrypted and never returned.



## OpenAPI

````yaml api-reference/openapi.v1.json PUT /mcp-oauth-apps
openapi: 3.1.0
info:
  title: Aether Public API
  version: 0.1.0
  description: >-
    The versioned, public Aether REST API. Authenticate with an `aether_`
    platform API key or a session token.
servers:
  - url: https://api.runaether.dev/v1
security:
  - bearerAuth: []
paths:
  /mcp-oauth-apps:
    put:
      tags:
        - mcp-servers
      summary: Save the organization's OAuth app for an issuer
      description: >-
        Org admins only. Stores the client id and secret of the OAuth app the
        organization registered at the issuer's authorization server.
        Re-entering the secret with the app's client id rotates it, and the
        connections made with the app stay; another client id replaces the app,
        and every connection made with the replaced one needs its owner to
        connect again (needs_reauth, revoked). The issuer's metadata is read
        first: the app is stored for the issuer it names, and Aether sends the
        secret to its token endpoint by client_secret_basic or
        client_secret_post as its token_endpoint_auth_methods_supported allows
        (mcp_oauth_app_auth_method_unsupported when it allows neither). Every
        server of the issuer in the organization then connects with the app,
        members' own connections and the organization's alike, unless the issuer
        offers Aether a client ID metadata document or dynamic client
        registration. The secret is encrypted and never returned.
      operationId: putMcpOAuthApp
      parameters:
        - description: >-
            The authorization server's issuer: the one the probe's
            oauth_app_required result names.
          explode: false
          in: query
          name: issuer
          required: true
          schema:
            description: >-
              The authorization server's issuer: the one the probe's
              oauth_app_required result names.
            maxLength: 2048
            minLength: 1
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PutMcpOAuthAppRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpOAuthAppResponse'
          description: OK
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ErrorResponse'
                  - $ref: '#/components/schemas/OrgAuthorizationErrorResponse'
          description: Forbidden
        '422':
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ErrorResponse'
                  - $ref: '#/components/schemas/McpServerErrorResponse'
          description: Unprocessable Entity
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Internal Server Error
components:
  schemas:
    PutMcpOAuthAppRequest:
      additionalProperties: false
      properties:
        client_id:
          description: Printable ASCII without spaces.
          maxLength: 512
          minLength: 1
          type: string
        client_secret:
          description: Printable ASCII without spaces. Stored encrypted and never returned.
          maxLength: 1024
          minLength: 1
          type: string
      required:
        - client_id
        - client_secret
      type: object
    McpOAuthAppResponse:
      additionalProperties: false
      properties:
        oauth_app:
          $ref: '#/components/schemas/McpOAuthApp'
      required:
        - oauth_app
      type: object
    ErrorResponse:
      additionalProperties: false
      properties:
        code:
          type: string
        error:
          minLength: 1
          type: string
        errors:
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type: array
      required:
        - error
      type: object
    OrgAuthorizationErrorResponse:
      additionalProperties: false
      properties:
        code:
          enum:
            - org_membership_required
            - org_role_insufficient
            - org_suspended
            - account_deleting
          type: string
        error:
          minLength: 1
          type: string
      required:
        - error
        - code
      type: object
    McpServerErrorResponse:
      additionalProperties: false
      properties:
        code:
          enum:
            - mcp_server_key_invalid
            - mcp_server_key_reserved
            - mcp_server_key_taken
            - mcp_server_display_name_invalid
            - mcp_server_url_invalid
            - mcp_server_runtime_invalid
            - mcp_server_package_invalid
            - mcp_server_version_unpinned
            - mcp_server_args_invalid
            - mcp_server_env_invalid
            - mcp_server_kind_change_refused
            - mcp_server_address_refused
            - mcp_server_unreachable
            - mcp_server_not_mcp
            - mcp_server_auth_unsupported
            - mcp_server_auth_discovery_failed
            - mcp_server_response_too_large
            - mcp_server_auth_change_conflict
            - mcp_credential_policy_required
            - mcp_credential_policy_not_applicable
            - mcp_credential_policy_org_unavailable
            - mcp_server_api_key_not_applicable
            - mcp_connection_static_secret_not_accepted
            - mcp_connection_secret_invalid
            - mcp_connection_server_changed
            - mcp_server_aether_managed
            - mcp_connection_github_not_connected
            - mcp_connection_org_not_offered
            - mcp_server_headers_invalid
            - mcp_connection_oauth_not_accepted
            - mcp_oauth_not_advertised
            - mcp_oauth_pkce_unsupported
            - mcp_oauth_app_required
            - mcp_oauth_registration_failed
            - mcp_server_plugin_bundled
            - mcp_repo_config_invalid
            - mcp_oauth_app_issuer_invalid
            - mcp_oauth_app_invalid
            - mcp_oauth_app_auth_method_unsupported
          type: string
        error:
          minLength: 1
          type: string
      required:
        - error
        - code
      type: object
    McpOAuthApp:
      additionalProperties: false
      properties:
        client_id:
          minLength: 1
          type: string
        issuer:
          description: The authorization server's issuer, exactly as its metadata names it.
          format: uri
          type: string
        token_endpoint_auth_method:
          description: >-
            How Aether sends the client secret to the token endpoint:
            client_secret_basic when the issuer's
            token_endpoint_auth_methods_supported lists it or lists nothing,
            else client_secret_post.
          enum:
            - client_secret_basic
            - client_secret_post
          type: string
        updated_at:
          format: date-time
          type: string
      required:
        - issuer
        - client_id
        - token_endpoint_auth_method
        - updated_at
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
  securitySchemes:
    bearerAuth:
      bearerFormat: JWT
      scheme: bearer
      type: http

````