> ## Documentation Index
> Fetch the complete documentation index at: https://docs.interchange.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Register browser origin

> Register an exact HTTPS browser origin for browser-based MCP and OAuth calls. Provide only the origin, such as `https://mcp.example.com`; do not include paths, redirects, wildcards, query strings, fragments, or non-HTTPS schemes. Admin-only.



## OpenAPI

````yaml /v2/storefront-api-v2.yaml post /browser-origins
openapi: 3.0.0
info:
  title: Scope3 Storefront API
  version: 2.0.0
  description: |-
    REST API for partners to manage storefronts, inventory sources, and billing.

    ## Authentication

    All endpoints require a Bearer token in the Authorization header:
    ```
    Authorization: Bearer your-api-key
    ```

    ## Base URL

    `https://api.interchange.io/api/v2/storefront`

    ## For AI Agents

    AI agents can use the MCP endpoint at `/mcp/v2/storefront` with three tools:
    - `initialize`: Start an MCP session
    - `api_call`: Make REST API calls
    - `ask_about_capability`: Learn about API features
servers:
  - url: https://api.interchange.io/api/v2/storefront
    description: Production server
security: []
tags:
  - name: Account
    description: Account management, service tokens, and preferences
  - name: Storefront
    description: Manage storefront and inventory sources
  - name: Storefront Agents
    description: List and manage registered sales, signals, and outcomes agents
  - name: Storefront Activity
    description: Audit log of configuration and inventory changes on the storefront
  - name: Storefront Billing
    description: Payout bank details and billing configuration for storefronts
  - name: AI Usage
    description: Storefront AI token usage visibility by model
  - name: MCP
    description: Model Context Protocol endpoints
paths:
  /browser-origins:
    servers:
      - url: https://api.interchange.io/api/v2
        description: Production server
    post:
      tags:
        - Account
      summary: Register browser origin
      description: >-
        Register an exact HTTPS browser origin for browser-based MCP and OAuth
        calls. Provide only the origin, such as `https://mcp.example.com`; do
        not include paths, redirects, wildcards, query strings, fragments, or
        non-HTTPS schemes. Admin-only.
      operationId: createBrowserOrigin
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateBrowserOriginBody'
      responses:
        '201':
          description: Register browser origin
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BrowserOrigin'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Admin role required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    CreateBrowserOriginBody:
      type: object
      properties:
        origin:
          description: >-
            Exact HTTPS browser origin to allow for browser MCP/OAuth calls. Do
            not include a path, query, fragment, wildcard, or userinfo.
          example: https://mcp.example.com
          type: string
          minLength: 1
          maxLength: 255
          pattern: ^https:\/\/[^/?#@]+$
        label:
          description: Optional human-readable label
          type: string
          minLength: 1
          maxLength: 120
      required:
        - origin
    BrowserOrigin:
      type: object
      properties:
        id:
          description: Browser origin registration ID
          type: string
        customerId:
          description: Customer account that owns this origin
          type: integer
          maximum: 9007199254740991
          minimum: 1
        origin:
          description: Exact browser origin, e.g. https://mcp.example.com
          type: string
          format: uri
        label:
          description: Optional human-readable label for this origin
          nullable: true
          type: string
        createdByUserId:
          description: User who registered the origin, when known
          nullable: true
          type: integer
          maximum: 9007199254740991
          minimum: 1
        createdAt:
          description: When this origin was registered
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        updatedAt:
          description: When this origin was last updated
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
      required:
        - id
        - customerId
        - origin
        - label
        - createdByUserId
        - createdAt
        - updatedAt
      additionalProperties: false
    ErrorResponse:
      description: Standard error response
      type: object
      properties:
        data:
          type: string
          nullable: true
          enum:
            - null
        error:
          $ref: '#/components/schemas/ApiError'
      required:
        - data
        - error
      additionalProperties: false
    ApiError:
      description: Structured error object
      type: object
      properties:
        code:
          description: Machine-readable error code
          type: string
        message:
          description: Human-readable error message
          type: string
        field:
          description: Field path associated with the error
          type: string
        details:
          description: Additional error context
          type: object
          additionalProperties: {}
      required:
        - code
        - message
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key or access token

````