Agent gateway
Agent gateway documentation
The agent gateway is a separate domain at agents.jobsai.cz. Clients register on the main website, then obtain a DPoP-bound OAuth2 token via client-credentials.
How the agent gateway works
- The developer fills in the registration and confirms their email.
- The developer provides a public DPoP key (JWK or JWKS URL) during registration. After e-mail confirmation the system shows client_id and client_secret once.
- The agent requests a token at agents.jobsai.cz/v1/oauth/token with a DPoP proof.
- The MCP/A2A/ACP endpoints verify the DPoP token binding and separate candidate consent.
DPoP: the htu claim must equal the exact request URL. The nonce is optional - omit it, or echo the latest value from the DPoP-Nonce response header (a self-generated nonce is rejected). The authoritative token endpoint is in the OAuth metadata.
Idempotency: every write operation (MCP submit_application, withdraw_application, propose_action and execute_approved_action, ACP POST /runs and /runs/{id}/cancel) requires an Idempotency-Key header (UUID or an 8-255 char [a-zA-Z0-9_-] token). Without it the API returns 400 idempotency_key_required. Streaming tools (subscribe, stream_matches) return only a pointer via tools/call - open the stream itself with a second request using Accept: text/event-stream.
Quickstart: connect an MCP client
From zero to the first call in 3 steps. The server runs at agents.jobsai.cz (streamable HTTP); read tools need a registered agent, writes additionally need a candidate consent envelope.
1. Register your agent
The agent registration page issues a client_id and client_secret (shown once). Tokens come from the OAuth 2.1 client credentials flow with RFC 8414 discovery (links below).
2. Add the server to your client
Claude Desktop and compatible clients: add to your mcpServers configuration:
{
"mcpServers": {
"jobsai": {
"type": "http",
"url": "https://agents.jobsai.cz/v1/mcp"
}
}
}Claude Code (CLI):
claude mcp add --transport http jobsai https://agents.jobsai.cz/v1/mcp3. Make your first call
Once connected, the client loads tools/list. Start with search_jobs (live listings search) and get_job (detail). Write tools require a consent envelope - the candidate grants it in the Agent access section of their account.
Tools overview
| Tool | Required access |
|---|---|
| search_jobs | jobs:read |
| get_job | jobs:read |
| submit_application | applications:write + consent envelope |
| get_application_status | applications:read + consent envelope |
| list_applications | applications:read + consent envelope |
| withdraw_application | applications:write + consent envelope |
| saved_jobs | applications:read/write + consent envelope |
| subscribe (SSE) | applications:read + consent envelope |
| stream_matches (SSE) | jobs:read |
| propose_action | scope of the proposed action + consent envelope |
| get_action_proposal | scope of the proposed action + consent envelope |
| execute_approved_action | scope of the proposed action + consent envelope |
Actions the candidate confirms
The propose_action, get_action_proposal and execute_approved_action tools form the confirmation loop. The agent only proposes an action; the candidate sees the exact command in their JobsAI account (agent access, approvals section), may edit it and confirm it, and only then does the agent execute exactly that command, once. The long-lived consent envelope does not replace that confirmation. The required scope is the scope of the proposed action and must be present both in the token and in the envelope. The feature is available only where the operator enabled it; elsewhere the tools return approvals_unavailable.
Example prompts
- Find 5 open cook positions in Prague on JobsAI and compare their salary ranges.
- Get the details of JobsAI job <id> and summarize the requirements in Czech.
- With my JobsAI consent envelope, apply to job <id> and then check the application status.
The server is also listed in the official MCP registry as cz.jobsai/jobsai.
Links
- MCP server (Streamable HTTP)
- OAuth metadata (RFC 8414)
- OAuth protected resource (RFC 9728)
- JWKS
- A2A agent card (transport discovery)
- ACP manifest (agent.json)
- ACP OpenAPI
- Discovery index (MCP + A2A + ACP)
- Machine-readable compliance.json
A machine-readable compliance summary (provider, risk category, human oversight, contact and data-subject rights) is available at /compliance.json.
The messages:write scope is reserved for a future messaging endpoint and is not issued in tokens yet.