Begin the OAuth handshake for an External MCP Connection
curl --request GET \
--url https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"status": "connected",
"authorizeUrl": "<string>"
}{
"error": "unauthorized"
}{
"error": "connection_not_found",
"message": "<string>"
}{
"error": "mcp_oauth_configuration_required",
"message": "<string>",
"callbackUrl": "<string>",
"clientMetadataUrl": "<string>",
"manualRequirements": [
"<string>"
]
}{
"error": "oauth_handshake_failed",
"message": "<string>",
"diagnostic": {
"referenceId": "<string>",
"phase": "CONFIGURATION",
"category": "<string>",
"code": "<string>",
"highestPassed": "configured",
"retryable": true,
"actionOwner": "openwork",
"operatorAction": "<string>",
"message": "<string>",
"httpStatus": 349,
"operationPhase": "CONFIGURATION",
"outbound": {
"origin": "<string>",
"pathHash": "<string>"
},
"providerRequestId": "<string>",
"providerStatus": 0,
"providerCode": "<string>",
"payloadBytes": 0,
"jsonRpcCode": 0,
"connectUrl": "<string>"
},
"callbackUrl": "<string>"
}Authentication
Begin the OAuth handshake for an External MCP Connection
Runs RFC 9728 discovery, dynamic client registration if needed, and returns an authorize URL to redirect the admin’s browser to.
GET
/
v1
/
mcp-connections
/
{connectionId}
/
connect
/
start
Begin the OAuth handshake for an External MCP Connection
curl --request GET \
--url https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/mcp-connections/{connectionId}/connect/start")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"status": "connected",
"authorizeUrl": "<string>"
}{
"error": "unauthorized"
}{
"error": "connection_not_found",
"message": "<string>"
}{
"error": "mcp_oauth_configuration_required",
"message": "<string>",
"callbackUrl": "<string>",
"clientMetadataUrl": "<string>",
"manualRequirements": [
"<string>"
]
}{
"error": "oauth_handshake_failed",
"message": "<string>",
"diagnostic": {
"referenceId": "<string>",
"phase": "CONFIGURATION",
"category": "<string>",
"code": "<string>",
"highestPassed": "configured",
"retryable": true,
"actionOwner": "openwork",
"operatorAction": "<string>",
"message": "<string>",
"httpStatus": 349,
"operationPhase": "CONFIGURATION",
"outbound": {
"origin": "<string>",
"pathHash": "<string>"
},
"providerRequestId": "<string>",
"providerStatus": 0,
"providerCode": "<string>",
"payloadBytes": 0,
"jsonRpcCode": 0,
"connectUrl": "<string>"
},
"callbackUrl": "<string>"
}Authorizations
bearerAuthdenApiKey
Session token passed as Authorization: Bearer <session-token> for user-authenticated Den routes.
Path Parameters
Den TypeID with 'emc_' prefix and a 26-character base32 suffix.
Required string length:
30Was this page helpful?