Knowledge Base
Browse the concepts behind Truestamp. Follow the links between concepts, or search across everything.
Tagged: oauth
13
API
Beacon API
The authenticated programmatic beacon surfaces - JSON:API endpoints under /api/json/beacons (list, latest, by id, by hash), the equivalent GraphQL queries, the four-field beacon object, error and rate-limit behavior including the rate_limited code, and beacon proof generation by block id.
Console WebSocket Surface
The authenticated multiplexed console WebSocket at /console/websocket, its stream catalog, inbound commands (subscribe, items.create, items.watch), outbound stream events, first-event-immediate burst coalescer, per-connection stream and payload caps, and per-account command and outbound rate limits.
GraphQL API
The authenticated GraphQL endpoint at /gql and its interactive playground, requiring an API key or OAuth bearer token, with queries and mutations auto-generated from the Truestamp resource domains and an introspectable schema.
JSON:API HTTP Surface
The authenticated JSON:API REST surface at /api/json, its API-key or OAuth bearer auth, the OpenAPI spec plus Swagger UI and ReDoc discovery pages, resource-oriented endpoints, tenant selection, filtering, and pagination conventions.
Glossary
CLI (truestamp)
The open-source truestamp command-line client, a single static binary for macOS, Linux, and Windows that submits items, downloads proof bundles, and verifies proofs fully offline without an account, signing in through the browser as a pre-registered OAuth 2.1 PKCE client.
Console (WebSocket)
The authenticated multiplexed WebSocket surface at /console/websocket for real-time programmatic access, where clients subscribe to live streams, issue commands such as items.create and items.watch, and receive stream events under per-connection rate, stream, and payload limits.
GraphQL
Truestamp's authenticated GraphQL endpoint at /gql with an interactive playground at /gql/playground, accepting an API key or OAuth 2.1 bearer token, whose introspectable schema of queries and mutations is generated from the same resource domains as the JSON:API.
JSON:API
Truestamp's authenticated REST surface at /api/json following the JSON:API specification, with API-key or OAuth 2.1 bearer authentication, an OpenAPI spec rendered by Swagger UI and ReDoc, and resource endpoints with standard filtering, sorting, and pagination.
MCP (Model Context Protocol)
The Model Context Protocol, which connects an LLM agent (Claude Code, IDE agents, Claude Desktop) to a Truestamp account at /mcp, a three-tool code-mode surface authenticated exclusively by OAuth 2.1 with an mcp:read/mcp:write scope split and a preview-then-submit write flow.
OAuth 2.1
Truestamp's built-in authorization server (authorize, token, register, revoke endpoints with RFC 8414/9728 discovery) issuing audience-bound access tokens and rotating refresh tokens via PKCE S256 consent, with per-surface mcp/api/console read and write scopes; the only credential MCP accepts.
Integrations
MCP Server for LLM Agents
The authenticated Truestamp MCP server that connects an LLM agent (Claude Code, IDEs, Claude Desktop) over OAuth 2.1 with three code-mode tools, a mcp:read/mcp:write scope split, and a preview-then-submit confirm-before-write flow, alongside a public setup page on the same address.
OAuth 2.1 Authorization Server
Truestamp's OAuth 2.1 authorization server with authorize, token, register, and revoke endpoints, RFC 8414/9728 discovery documents, PKCE S256, audience-bound tokens, rotating refresh tokens, and per-surface mcp/api/console scopes for authenticating a CLI or MCP agent.
Truestamp CLI
The open-source truestamp CLI, a single static binary for macOS, Linux, and Windows that creates, downloads, and verifies cryptographic proofs from the terminal, installs via curl, Homebrew, or Go, signs in with browser-based OAuth 2.1 PKCE, and verifies proofs fully offline.