client_id, a client secret, up to ten redirect URIs, access to the owner scopes and a cap on sign-ups per owner. Everything here is also available under Sign-in apps in the dashboard.
All calls take an organization key (alk_…) with the applications:manage capability.
Register an application
POST /api/v1/applications creates the application and returns the client secret once.
Register an application
string
The
client_id your app sends to the issuer.string
Shown once. Store it in your app’s configuration.
POST https://id.agent-loadout.com/register with RFC 7591 client metadata (client_name, redirect_uris, client_uri, logo_uri) and the organization key as the Bearer token.
List, read, change and delete
GET /api/v1/applicationslists the organization’s applications.GET /api/v1/applications/:idreads one.PATCH /api/v1/applications/:idchangesname,redirect_uris,website,logo_url,description,listed,initiate_login_uriormax_signups_per_owner; omitted fields keep their value,nullclears a URL, the description or the cap.DELETE /api/v1/applications/:idremoves it. Sign-ins through it stop working; agents keep the accounts they created at your app.
Directory and agent-started sign-ins
Setlisted: true with a description and website to appear in the public directory of apps that accept Sign in with Agent Loadout, which agents also read through list_sign_in_apps and GET /api/v1/sign-in-apps.
Set initiate_login_uri to the route where your app starts a sign-in with Agent Loadout as the provider. Agents can then sign in from their side: start_sign_in grants your app and sends the agent’s browser to that URL with iss and login_hint, and the sign-in completes without anyone acting. The directory marks such apps with can_start_sign_in.
Rotate the secret
POST /api/v1/applications/:id/secret replaces the client secret. The old one stops working at once and the new one is returned once.
Sign-in history
GET /api/v1/applications/:id/history?limit=50 lists recent sign-ins at the application, newest first: the outcome (completed, approved, denied, expired, pending), the agent’s opaque sub, the granted scopes and the times. It never names the agent’s organization.
Sign-ups per owner
max_signups_per_owner counts the agents of one organization that hold an approval for your app. The next agent of that organization is refused before approval, and your callback receives error=access_denied&error_description=signup_limit_reached. 0 pauses new agents while existing ones keep signing in; null removes the cap.