Authentication
Public data needs no sign-in. To act on your account, use OAuth 2.1 (apps and AI assistants) or a personal API key (your own scripts). Both are sent as Authorization: Bearer …. Cookies are never used by the API.
Scopes
read- Read public data (listings, categories, launches, leaderboards, blog). Not needed for anonymous reads.
account:read- See your account, your listings, drafts and orders
listings:write- Submit new listings and edit your own drafts and listings
orders:write- Build orders for paid products and get a checkout link you pay yourself
OAuth 2.1
- Issuer
https://debutdirectory.com- Server metadata
- /.well-known/oauth-authorization-server (RFC 8414)
- Resource metadata
- /.well-known/oauth-protected-resource/mcp and /.well-known/oauth-protected-resource (RFC 9728)
- Authorize
https://debutdirectory.com/oauth/authorize: authorization code with PKCE (S256 only); the response carriesiss(RFC 9207)- Token
https://debutdirectory.com/oauth/token:authorization_codeandrefresh_tokengrants- Registration
- Client ID metadata documents (an https
client_idURL), or dynamic registration athttps://debutdirectory.com/oauth/register(RFC 7591) - Revoke
https://debutdirectory.com/oauth/revoke(RFC 7009)- Resource
- Send
resource=https://debutdirectory.com/mcp(orhttps://debutdirectory.com) on authorize and token requests (RFC 8707). Tokens work only on Debut Directory. - Lifetimes
- Access tokens 60 minutes; refresh tokens 30 days, rotated on every use. Re-using an old refresh token signs the app out.
Redirect URIs must be https, a loopback address (http://127.0.0.1 or http://localhost, any port) or an app's own scheme. You can see and disconnect apps under API keys and connected apps.
Personal API keys
Create a key under API keys, choose its access, copy it once, and send it as Authorization: Bearer lk_…. We store only a fingerprint of it, so a lost key cannot be shown again: revoke it and make a new one.
curl "https://debutdirectory.com/api/v1/me" -H "Authorization: Bearer $API_KEY"