{"issuer":"https://api.1claw.co","jwks_uri":"https://api.1claw.co/.well-known/jwks.json","token_endpoint":"https://api.1claw.co/v1/oauth/token","authorization_endpoint":"https://1claw.co/oauth/authorize","userinfo_endpoint":"https://api.1claw.co/v1/oauth/userinfo","id_token_signing_alg_values_supported":["EdDSA","RS256"],"subject_types_supported":["public"],"response_types_supported":["id_token","code"],"grant_types_supported":["authorization_code"],"code_challenge_methods_supported":["S256"],"token_endpoint_auth_methods_supported":["private_key_jwt","client_secret_post","none"],"scopes_supported":["openid","profile","email","wallet"],"claims_supported":["sub","iss","aud","exp","iat","jti","org","scopes","vault_ids","email","name","wallet_address","nonce"],"service_documentation":"https://docs.1claw.co","federation":{"token_endpoint":"https://api.1claw.co/v1/auth/federated-token","grant_types_supported":["urn:ietf:params:oauth:grant-type:token-exchange"],"description":"RFC 8693 token exchange for OIDC federation (e.g. Anthropic WIF). Exchange a 1claw agent JWT or API key for an RS256 OIDC JWT with a caller-specified audience."},"agent_auth":{"docs":"https://1claw.co/auth.md","register_uri":"https://api.1claw.co/v1/agents/enroll","token_uri":"https://api.1claw.co/v1/auth/agent-token","revocation_uri":"https://api.1claw.co/v1/auth/token","identity_types_supported":["identity_assertion","anonymous"],"assertion_types_supported":["api_key","mtls","oidc_client_credentials"],"identity_assertion":{"assertion_types_supported":["api_key","mtls","oidc_client_credentials"],"token_uri":"https://api.1claw.co/v1/auth/agent-token","register_uri":"https://api.1claw.co/v1/agents/enroll","revocation_uri":"https://api.1claw.co/v1/auth/token","api_key":{"prefix":"ocv_","exchange_endpoint":"https://api.1claw.co/v1/auth/agent-token","request_schema":{"type":"object","required":["api_key"],"properties":{"api_key":{"type":"string","pattern":"^ocv_"},"agent_id":{"type":"string","format":"uuid","description":"Optional — resolved automatically from key prefix"}}},"response_fields":["access_token","agent_id","vault_ids","expires_in"]},"mtls":{"description":"Mutual TLS client certificate authentication (planned)","status":"planned"},"oidc_client_credentials":{"description":"OIDC client credentials flow (planned)","status":"planned"}},"anonymous":{"register_uri":"https://api.1claw.co/v1/agents/enroll","description":"Self-enrollment without pre-existing credentials","request_schema":{"type":"object","required":["name","human_email"],"properties":{"name":{"type":"string"},"human_email":{"type":"string","format":"email"},"description":{"type":"string"}}},"response_fields":["agent_id","message"],"note":"API key is emailed to human_email, never returned in response"}}}