# Future Integration Requirements

Status: not live. This is a design boundary, not a published OpenAI plugin, hosted connector, public MCP endpoint or promise of current discovery metadata. Do not call hypothetical metadata endpoints or advertise an internal MCP plan as an available integration. These requirements are intentionally excluded from `llms-full.txt` and live OpenAPI operations.

## OAuth Metadata and Registration

Before a future OpenAI-facing OAuth integration is enabled, publish authorization-server metadata with a stable HTTPS issuer and the actual authorization, token and supported grant information. Publish protected-resource metadata identifying the exact resource and trusted authorization server. Metadata must contain public protocol information only, never client secrets, keys with private material, access tokens or account data.

Use preregistered clients with approved redirect URIs. No open dynamic client registration is promised or assumed. Reject arbitrary redirect URIs and unregistered clients. The issuer in metadata, token validation and trusted server configuration must agree; do not derive a trusted issuer from an unvalidated request host.

## PKCE and Resource Audience

For a future interactive authorization-code integration, require PKCE with `S256`, exact redirect URI validation and transaction-bound state. Authenticate the user and require explicit consent to the actual scopes. Device flow and client credentials are distinct current flows, not substitutes for an authorization-code/PKCE compatibility requirement.

Bind authorization and tokens to the intended resource using the OAuth `resource` parameter and validate the resulting token audience at the resource server. Reject tokens for another resource or issuer, even if the signature is otherwise valid. Do not pass PureStats tokens through to unrelated upstream services. Short token lifetimes, revocation, limited scopes and account/site authorization remain required.

The underlying protocol requirements are described in [authorization-server metadata, RFC 8414](https://www.rfc-editor.org/rfc/rfc8414), [protected-resource metadata, RFC 9728](https://www.rfc-editor.org/rfc/rfc9728), [PKCE, RFC 7636](https://www.rfc-editor.org/rfc/rfc7636) and [resource indicators, RFC 8707](https://www.rfc-editor.org/rfc/rfc8707.html). Platform-specific compatibility must be checked against the actual integration contract before release.
