openapi: 3.2.0 info: title: FeedOracle Compliance Evidence MCP Auth API version: 8.4.1+truthrepair.r1 description: 'FeedOracle Compliance Evidence Infrastructure — 44 MCP servers, 590+ evidence tools across 17 data sources. DORA, MiCA, AMLR and CSRD compliance evidence APIs. ES256K-signed responses, blockchain-anchored. Canonical metrics: https://feedoracle.io/data/feedoracle-metrics.json.' contact: email: support@feedoracle.io url: https://feedoracle.io/contact.html license: name: Proprietary termsOfService: https://feedoracle.io/terms.html servers: - url: https://api.feedoracle.io description: Production security: [] tags: - name: MCP Auth paths: /mcp/register: post: tags: - MCP Auth summary: Dynamic Client Registration (RFC 7591) description: Register an M2M client. Pass grant_types=["client_credentials"] for agent use. requestBody: required: true content: application/json: schema: type: object properties: client_name: type: string grant_types: type: array items: type: string example: - client_credentials redirect_uris: type: array items: type: string scope: type: string example: mcp:read required: - client_name - grant_types - redirect_uris responses: '201': description: Client registered content: application/json: schema: type: object properties: client_id: type: string client_secret: type: string grant_types: type: array items: type: string operationId: postMcpRegister x-operation-id-source: derived /mcp/token: post: tags: - MCP Auth summary: OAuth 2.0 Token (client_credentials + authorization_code) description: 'Issue Bearer token. For M2M: grant_type=client_credentials, no browser required.' requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object properties: grant_type: type: string enum: - client_credentials - authorization_code - refresh_token client_id: type: string client_secret: type: string scope: type: string code: type: string description: For authorization_code flow only required: - grant_type example: grant_type: client_credentials client_id: fo_client_abc123 client_secret: fo_secret_xyz scope: mcp:read responses: '200': description: Bearer token content: application/json: schema: type: object properties: access_token: type: string token_type: type: string example: Bearer expires_in: type: integer example: 3600 tier: type: string example: access_token: fo_cc_... token_type: Bearer expires_in: 3600 tier: free operationId: postMcpToken x-operation-id-source: derived /mcp/revoke: post: tags: - MCP Auth summary: Token Revocation (RFC 7009) description: Revoke an access token. Returns HTTP 200 + empty body on success (RFC 7009). requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object properties: token: type: string client_id: type: string client_secret: type: string required: - token responses: '200': description: Revoked (empty body) operationId: postMcpRevoke x-operation-id-source: derived components: securitySchemes: ApiKeyAuth: type: apiKey in: header name: X-API-Key description: Required for v1 data endpoints. Get at /pricing.html BearerAuth: type: http scheme: bearer bearerFormat: JWT description: OAuth 2.0 Bearer token from POST /mcp/token bearerAuth: type: http scheme: bearer description: FeedOracle OAuth 2.1 Bearer token. Obtain via /mcp/register (Dynamic Client Registration, RFC 7591). x-nomos-trust-chain: model: S0-S10 manifest: https://agentnomos.com/.well-known/nomos-capabilities.json