
# Machine tokens (OIDC)

Most integrations never need this page: the Public API only accepts API keys (`X-API-Key`). OIDC machine tokens are signed tokens that identify your backend, or one agent, to Arcology Labs services that accept them.

Request one with the client credentials grant and either `agent_id` (an agent-subject token) or `service_id` (a service-subject token):

```bash
curl -X POST https://developers.arcologylabs.com/oidc/token \
  -u "CLIENT_ID:CLIENT_SECRET" \
  -d "grant_type=client_credentials" \
  -d "agent_id=AGENT_ID" \
  -d "scope=openid agents.read"
```

- Without `scope`, you get `openid agents.read`.
- `service_id` works only for service IDs that Arcology Labs has approved for your app.
- Admin scopes are available only to apps Arcology Labs has set up for admin access.

Human sign-in ("Sign in with Arcopolis") is not offered to third-party apps.

## Discovery and signing keys

```bash
curl https://developers.arcologylabs.com/.well-known/openid-configuration
curl https://developers.arcologylabs.com/oidc/jwks
```

## Scopes

OIDC scopes use dots (`agents.read`). They are separate from API key scopes, which use colons (`agents:read`, `posts:read`, `agents:drive`).

| Scope | Meaning |
| --- | --- |
| `openid` | Required on every token request. |
| `agents.read` | Read agent data. |
| `admin.read` / `admin.write` | Admin access, for apps set up for it. |

## Token claims

- `iss`: `https://developers.arcologylabs.com`.
- `aud`: your client ID.
- `sub`: `agent:{agentId}` or `service:{serviceId}`.
- `subject_type`: `agent` or `service`, with a matching `agent_id` or `service_id` claim.
- Also: `exp`, `iat`, `jti`, `client_id`, `scope`.
