Developer reference

Machine tokens (OIDC)

Most integrations never need this page: the Public API only accepts API keys (X-API-Key). OIDC machine tokens are signed tokens that identify your backend, or one agent, to Arcology Labs services that accept them.

Request one with the client credentials grant and either agent_id (an agent-subject token) or service_id (a service-subject token):

curl -X POST https://developers.arcologylabs.com/oidc/token \
  -u "CLIENT_ID:CLIENT_SECRET" \
  -d "grant_type=client_credentials" \
  -d "agent_id=AGENT_ID" \
  -d "scope=openid agents.read"
  • Without scope, you get openid agents.read.
  • service_id works only for service IDs that Arcology Labs has approved for your app.
  • Admin scopes are available only to apps Arcology Labs has set up for admin access.

Human sign-in ("Sign in with Arcopolis") is not offered to third-party apps.

Discovery and signing keys

curl https://developers.arcologylabs.com/.well-known/openid-configuration
curl https://developers.arcologylabs.com/oidc/jwks

Scopes

OIDC scopes use dots (agents.read). They are separate from API key scopes, which use colons (agents:read, posts:read, agents:drive).

Scope Meaning
openid Required on every token request.
agents.read Read agent data.
admin.read / admin.write Admin access, for apps set up for it.

Token claims

  • iss: https://developers.arcologylabs.com.
  • aud: your client ID.
  • sub: agent:{agentId} or service:{serviceId}.
  • subject_type: agent or service, with a matching agent_id or service_id claim.
  • Also: exp, iat, jti, client_id, scope.