Skip to main content
A registered application is a relying party of Sign in with Agent Loadout that your organization operates. It gets an opaque client_id, a client secret, up to ten redirect URIs, access to the owner scopes and a cap on sign-ups per owner. Everything here is also available under Sign-in apps in the dashboard. All calls take an organization key (alk_…) with the applications:manage capability.

Register an application

POST /api/v1/applications creates the application and returns the client secret once.
Register an application
string
The client_id your app sends to the issuer.
string
Shown once. Store it in your app’s configuration.
The same registration works through the OpenID Connect registration endpoint: POST https://id.agent-loadout.com/register with RFC 7591 client metadata (client_name, redirect_uris, client_uri, logo_uri) and the organization key as the Bearer token.

List, read, change and delete

  • GET /api/v1/applications lists the organization’s applications.
  • GET /api/v1/applications/:id reads one.
  • PATCH /api/v1/applications/:id changes name, redirect_uris, website, logo_url, description, listed, initiate_login_uri or max_signups_per_owner; omitted fields keep their value, null clears a URL, the description or the cap.
  • DELETE /api/v1/applications/:id removes it. Sign-ins through it stop working; agents keep the accounts they created at your app.

Directory and agent-started sign-ins

Set listed: true with a description and website to appear in the public directory of apps that accept Sign in with Agent Loadout, which agents also read through list_sign_in_apps and GET /api/v1/sign-in-apps. Set initiate_login_uri to the route where your app starts a sign-in with Agent Loadout as the provider. Agents can then sign in from their side: start_sign_in grants your app and sends the agent’s browser to that URL with iss and login_hint, and the sign-in completes without anyone acting. The directory marks such apps with can_start_sign_in.

Rotate the secret

POST /api/v1/applications/:id/secret replaces the client secret. The old one stops working at once and the new one is returned once.

Sign-in history

GET /api/v1/applications/:id/history?limit=50 lists recent sign-ins at the application, newest first: the outcome (completed, approved, denied, expired, pending), the agent’s opaque sub, the granted scopes and the times. It never names the agent’s organization.

Sign-ups per owner

max_signups_per_owner counts the agents of one organization that hold an approval for your app. The next agent of that organization is refused before approval, and your callback receives error=access_denied&error_description=signup_limit_reached. 0 pauses new agents while existing ones keep signing in; null removes the cap.