Skip to main content
1 operation on client.obo. Path parameters come first, positionally; the request body is last, as a plain object. Method names are snake_case in Python and camelCase in TypeScript, and resource names follow the same rule.
Call this with the person’s own bearer token, after they have consented to the agent. Consent runs over HTTP, and the SDK has no method for it: POST /secret/v1/oauth/start with {"provider": "obo-<agent_id>", "owner": "personal"}, open the returned authorization_url in a browser, then poll POST /secret/v1/oauth/complete with the attempt_id until it answers connected. Without consent the call returns 404 not_found, and so does another person’s token, which finds no grant. A grant that needs fresh consent returns 409 needs_consent. A machine credential (an API key or service account) or an agent’s delegated token gets 403, as does a grant whose agent was re-keyed after consent. The token carries that person’s full authority: keep it in memory, never log or store it, and mint again before expires_in runs out.

Operations

How the client is organised

Resources, call shapes, and errors.

Errors and retries

What the SDK raises, and which calls are safe to retry.