Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Path Parameters

id
string
required

Flow row ID

Response

Flow detail

Response for GET /api/oauth/per-user/flows/{id}. Mirrors the headers-side MCPHeadersFlowDetail — identity binding for display plus the bits the consent UI needs to decide its copy.

id
string
required
flow_mode
enum<string>
required
Available options:
user,
vk,
session
status
enum<string>
required
Available options:
pending,
authorized,
failed,
expired
mcp_client
object
required

Minimal MCP client view embedded in session rows.

oauth_config_id
string
required
expires_at
string<date-time>
required
created_at
string<date-time>
required
has_active_token
boolean
required

True when an active token already exists for the flow's binding. A pending flow with this set means OAuth was re-initiated unnecessarily; the consent page can render this as "already authenticated" instead of prompting again.

user_id
string | null
user
object | null

Minimal user view embedded on user-keyed session rows.

virtual_key
object | null

Minimal virtual-key view embedded in session rows.

session_id
string | null