# Platform API

> Health, your application, and delegated agent credentials.

## Delegate a short-lived REST credential for one consented subject

`POST /agent-credentials` on `https://api.finchnode.com/api/v1`

App-key only. Does not approve sharing consent. Parent revocation invalidates the delegated credential. MCP-audience OAuth tokens are not accepted by this REST API.

Body:

- `subject` (string, required)
- `categories` (string[], required)
- `purpose` (string, required)
- `durationSeconds` (integer)
- `operations` (string[])

Responses:

- `201`: Opaque credential, shown once. Store server-side.
- `401`: API key is missing, invalid, or revoked.
- `403`: Subject credentials cannot delegate, or requested scope exceeds active consent.

## Revoke an app-owned API-delegated credential

`DELETE /agent-credentials/{credentialId}` on `https://api.finchnode.com/api/v1`

Parameters:

- `credentialId` (path, string, required)

Responses:

- `204`: Credential revoked.
- `404`: Delegated credential not found for this application and environment.

## Check API availability

`GET /health` on `https://api.finchnode.com/api/v1` (no key)

Responses:

- `200`: API is available.

## Resolve the application and environment for the current key

`GET /app` on `https://api.finchnode.com/api/v1`

Responses:

- `200`: Current application.
- `401`: API key is missing, invalid, or revoked.
- `429`: Request budget exceeded.
