generated: '2026-09-19' method: searched source: https://www.aircover.ai/developers derived_from: openapi/aircover-openapi.yml docs: https://www.aircover.ai/developers discovery: oauth_authorization_server: https://api.aircover.ai/.well-known/oauth-authorization-server oauth_protected_resource: https://api.aircover.ai/.well-known/oauth-protected-resource saved: - well-known/aircover-oauth-authorization-server.json - well-known/aircover-oauth-protected-resource.json probed: '2026-09-19' summary: types: - oauth2 oauth2_flows: - authorizationCode dynamic_client_registration: true pkce: S256 api_keys: false note: >- The only public credential is an OAuth 2.0 bearer token minted by Aircover's own authorization server (issuer https://api.aircover.ai). There is no API-key scheme on the public agent surface. The customer REST API used by the aircover-pipeline CLI authenticates separately with username/password at POST /auth/login or a bearer token copied from the web app; that surface is customer-only and undocumented publicly. schemes: - name: oauth2 type: oauth2 flows: - flow: authorizationCode authorizationUrl: https://api.aircover.ai/oauth/authorize tokenUrl: https://api.aircover.ai/oauth/token refreshUrl: https://api.aircover.ai/oauth/token scopes: 1 registration_endpoint: https://api.aircover.ai/oauth/register revocation_endpoint: https://api.aircover.ai/oauth/revoke grant_types_supported: - authorization_code - refresh_token response_types_supported: - code code_challenge_methods_supported: - S256 token_endpoint_auth_methods_supported: - client_secret_basic - client_secret_post scopes_supported: - mcp description: >- OAuth 2.0 authorization code flow with PKCE (S256) and dynamic client registration (RFC 7591). Agents register a client at /oauth/register (redirect_uris required — a live POST with an empty body returned 400 invalid_client_metadata "redirect_uris is required"), send the user to /oauth/authorize, exchange the code at /oauth/token, and refresh without human intervention beyond the initial consent. A token's scope caps what the client may request and every request is additionally bounded by the authorizing user's own role and organization. Tokens are revocable at /oauth/revoke. challenge: >- Unauthenticated POST https://api.aircover.ai/mcp returned 401 with WWW-Authenticate: Bearer resource_metadata="https://api.aircover.ai/.well-known/oauth-protected-resource" (observed 2026-09-19 via the x-amzn-remapped-www-authenticate header on the API Gateway edge). sources: - openapi/aircover-openapi.yml - https://api.aircover.ai/.well-known/oauth-authorization-server - https://www.aircover.ai/developers end_user_sign_in: note: >- End users of the Aircover app sign in with Google OAuth, Microsoft OAuth (Azure AD) or a per-organization OIDC/SSO provider (Okta, Auth0, Azure AD B2C). Personal email domains are refused; new sign-ups receive a trial license. These are the identities an MCP client's OAuth consent screen delegates to; they are not themselves API credentials. methods: - Google OAuth (requests calendar scopes; Drive scopes optional for CMS indexing) - Microsoft OAuth / Azure AD (requests Microsoft Graph calendar scopes; OneDrive optional) - OIDC / SSO configured per customer organization source: https://www.aircover.ai/llms.txt