> ## Documentation Index
> Fetch the complete documentation index at: https://docs.summerengine.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Player MCP authorization server metadata (RFC 8414)

> Public clients only, authorization code with S256 PKCE, rotating refresh tokens.



## OpenAPI

````yaml scripts/reference/sources/openapi/player.json GET /.well-known/oauth-authorization-server
openapi: 3.1.0
info:
  title: Summer Player Game Platform API
  version: summer.player.games/v1
  description: >-
    Public Summer Games store reads, the connected-app OAuth endpoints, and the
    signed-in player's profile and preferences.
servers:
  - url: https://api.summer.games
security:
  - playerBearer: []
paths:
  /.well-known/oauth-authorization-server:
    get:
      summary: Player MCP authorization server metadata (RFC 8414)
      description: >-
        Public clients only, authorization code with S256 PKCE, rotating refresh
        tokens. 404 where Connected apps are not configured.
      operationId: getOAuthAuthorizationServerMetadata
      responses:
        '200':
          description: Authorization server metadata
          content:
            application/json:
              schema:
                type: object
                required:
                  - issuer
                  - authorization_endpoint
                  - token_endpoint
                  - registration_endpoint
                  - scopes_supported
                properties:
                  issuer:
                    type: string
                    format: uri
                  authorization_endpoint:
                    type: string
                    format: uri
                    description: The Summer Games web consent page
                  token_endpoint:
                    type: string
                    format: uri
                  registration_endpoint:
                    type: string
                    format: uri
                  scopes_supported:
                    type: array
                    items:
                      type: string
                      enum:
                        - player:read
                        - player:act
        '404':
          description: Connected apps are not configured here
      security: []
components:
  securitySchemes:
    playerBearer:
      type: http
      scheme: bearer
      description: >-
        A player access token. Store reads need no token. Other apps get a token
        through connected-app OAuth: register the client, let the player approve
        it on summer.games, then exchange the code at the token endpoint.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.