add_account_token
Attach one of YOUR OWN Google accounts to the pool using an oauth_token captured on the USER'S OWN machine (password/2FA never leave it). This is the self-serve onboarding path — no server-side browser, no SSH.
PREFERRED PATH — no oauth_token handling at all: call flow_status; its
`next_step.command` holds a PERSONAL one-line command per OS (mac / linux / win) with
the owner's ticket inside. RUN IT YOURSELF in the user's terminal. The script submits
the token to the server by itself and prints "Готово — аккаунт ... подключён"; you do
NOT call add_account_token afterwards. (The same command is shown to the user in the
cabinet: https://openflowmcp.com/account#accounts.) Node 22+ is the only requirement.
FALLBACK (only if flow_status has no command, or the script says it could not submit
automatically) — run the generic command, which has no ticket and just prints a line:
curl -sL https://openflowmcp.com/onboard_local.js | node
Windows PowerShell:
irm https://openflowmcp.com/onboard_local.js -OutFile o.js; node o.js
It opens the user's own Chrome at accounts.google.com/EmbeddedSetup. Tell them to log
in and press Accept, then wait until the page hangs on a spinner (normal, the token is
already issued), then go BACK to the terminal window running the script and press
Enter — the script grabs the token only after Enter, it does not do it by itself. Do
not close the browser window before that. The script prints ONE JSON line: {"status":200,"oauth_token":...,
"email":...}; with a personal command it also adds "submitted":true, which means the
account is already connected and you are done. Without "submitted":true, pass
oauth_token and email here.
If it prints "need_email": true, the account address could not be read off the page —
ask the user which Google account they just signed into and pass that as `email`, or
re-run with ONBOARD_EMAIL=them@gmail.com in front of the command.
The oauth_token is SINGLE-USE: if this call fails, the user must log in again for a
FRESH token — never retry the same one.
On success the account is bound to YOUR key's owner group and the worker picks it up
within ~30s (no restart). Adding an account is always allowed — even for a key that
has already spent its free quota, since that is a prerequisite, not a reward.
Only onboard accounts YOU control — a master token grants full account access.Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| Yes | |||
| reset_day | No | ||
| oauth_token | Yes |