> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agent-loadout.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Applications API: Register Apps for Sign in with Agent Loadout

> Create, change and delete the registered applications of your organization, rotate their client secrets and read their sign-in history. Requires an organization key with applications:manage.

A registered application is a relying party of Sign in with Agent Loadout that your organization operates. It gets an opaque `client_id`, a client secret, up to ten redirect URIs, access to the owner scopes and a cap on sign-ups per owner. Everything here is also available under **Sign-in apps** in the dashboard.

All calls take an organization key (`alk_…`) with the **applications:manage** capability.

## Register an application

`POST /api/v1/applications` creates the application and returns the client secret once.

```bash title="Register an application" theme={null}
curl -s -X POST https://agent-loadout.com/api/v1/applications \
  -H "Authorization: Bearer $AGENT_LOADOUT_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Acme Billing",
    "redirect_uris": ["https://acme.example/auth/callback", "http://localhost:3000/auth/callback"],
    "website": "https://acme.example",
    "max_signups_per_owner": 5
  }'
```

<ResponseField name="application.id" type="string">
  The `client_id` your app sends to the issuer.
</ResponseField>

<ResponseField name="client_secret" type="string">
  Shown once. Store it in your app's configuration.
</ResponseField>

The same registration works through the OpenID Connect registration endpoint: `POST https://id.agent-loadout.com/register` with RFC 7591 client metadata (`client_name`, `redirect_uris`, `client_uri`, `logo_uri`) and the organization key as the Bearer token.

## List, read, change and delete

* `GET /api/v1/applications` lists the organization's applications.
* `GET /api/v1/applications/:id` reads one.
* `PATCH /api/v1/applications/:id` changes `name`, `redirect_uris`, `website`, `logo_url`, `description`, `listed`, `initiate_login_uri` or `max_signups_per_owner`; omitted fields keep their value, `null` clears a URL, the description or the cap.
* `DELETE /api/v1/applications/:id` removes it. Sign-ins through it stop working; agents keep the accounts they created at your app.

## Directory and agent-started sign-ins

Set `listed: true` with a `description` and `website` to appear in the public [directory](https://agent-loadout.com/id/directory) of apps that accept Sign in with Agent Loadout, which agents also read through `list_sign_in_apps` and `GET /api/v1/sign-in-apps`.

Set `initiate_login_uri` to the route where your app starts a sign-in with Agent Loadout as the provider. Agents can then sign in from their side: `start_sign_in` grants your app and sends the agent's browser to that URL with `iss` and `login_hint`, and the sign-in completes without anyone acting. The directory marks such apps with `can_start_sign_in`.

## Rotate the secret

`POST /api/v1/applications/:id/secret` replaces the client secret. The old one stops working at once and the new one is returned once.

## Sign-in history

`GET /api/v1/applications/:id/history?limit=50` lists recent sign-ins at the application, newest first: the outcome (`completed`, `approved`, `denied`, `expired`, `pending`), the agent's opaque `sub`, the granted scopes and the times. It never names the agent's organization.

## Sign-ups per owner

`max_signups_per_owner` counts the agents of one organization that hold an approval for your app. The next agent of that organization is refused before approval, and your callback receives `error=access_denied&error_description=signup_limit_reached`. `0` pauses new agents while existing ones keep signing in; `null` removes the cap.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.