generate_token
Generate an OAuth2 access token for a user to authenticate MCP clients, enabling access to protected tools. Supports scopes, extra claims, and expiration.
Instructions
Generate an OAuth2 access token for a user
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| scope | No | Space-separated OAuth scopes (optional). Include 'openid' to also receive an ID Token; the scope is persisted in the refresh token so refreshing re-issues an ID Token (OIDC Core §12.2) | |
| username | Yes | Username to generate token for | |
| extra_claims | No | Additional claims to include in the token | |
| id_token_claims | No | Claim names to embed in the ID Token, mirroring the OIDC `claims` request parameter (§5.5). Requires an 'openid' scope. Resolved from the user (e.g. 'email', 'preferred_username', or a custom attribute); names nanoidp cannot supply are skipped. | |
| userinfo_claims | No | Claim names /userinfo should return for this access token, mirroring the `userinfo` member of the OIDC `claims` request parameter (§5.5). Stamped on the access token as `req_userinfo_claims` and honoured by /userinfo even under a stricter profile that would scope-gate them out. | |
| expires_in_minutes | No | Token expiration in minutes (optional, default: 60) |