> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apostra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a publisher-owned Agent Source

> Creates or safely reuses one publisher-owned Source from the connection contract published for an accepted referral. It does not authorize, accept, validate, activate, or certify the connection.



## OpenAPI

````yaml /v2/storefront-api-v2.yaml post /provider/client-referrals/source
openapi: 3.0.0
info:
  title: Scope3 Storefront API
  version: 2.0.0
  description: >-
    REST API for partners to manage Seller Accounts, inventory sources, and
    billing.


    ## Authentication


    All endpoints require a Bearer token in the Authorization header:

    ```

    Authorization: Bearer your-api-key

    ```


    ## Base URL


    `https://api.interchange.io/api/v2/storefront`


    ## For AI Agents


    AI agents can use the MCP endpoint at `/mcp/v2/storefront` with three tools:

    - `initialize`: Start an MCP session

    - `api_call`: Make REST API calls

    - `ask_about_capability`: Learn about API features
servers:
  - url: https://api.interchange.io/api/v2/storefront
    description: Production server
security: []
tags:
  - name: Account
    description: Account management, service tokens, and preferences
  - name: Asks
    description: >-
      What you are waiting on Scope3 for — support, product, and supply asks in
      one list
  - name: Storefront
    description: Manage storefront and inventory sources
  - name: Storefront Agents
    description: List and manage registered sales, signals, and outcomes agents
  - name: Storefront Activity
    description: Audit log of configuration and inventory changes on the storefront
  - name: Storefront Billing
    description: Payout bank details and billing configuration for Seller Accounts
  - name: AI Usage
    description: Seller Account AI token usage visibility by model
  - name: MCP
    description: Model Context Protocol endpoints
paths:
  /provider/client-referrals/source:
    servers:
      - url: /api/v2
        description: Shared customer API base URL
    post:
      tags:
        - Storefront
      summary: Create a publisher-owned Agent Source
      description: >-
        Creates or safely reuses one publisher-owned Source from the connection
        contract published for an accepted referral. It does not authorize,
        accept, validate, activate, or certify the connection.
      operationId: createProviderClientReferralSource
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateProviderClientReferralSource'
      responses:
        '200':
          description: Create a publisher-owned Agent Source
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProviderClientReferralSourceCreation'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Accepting publisher administrator required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Accepted invitation or contract not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: The referral Source already has different connection values.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    CreateProviderClientReferralSource:
      type: object
      properties:
        token:
          type: string
          pattern: ^[A-Za-z0-9_-]{43}$
        connection:
          type: object
          properties:
            contract:
              type: object
              properties:
                id:
                  type: string
                  minLength: 1
                  maxLength: 128
                  pattern: ^[a-z][a-z0-9_-]*$
                version:
                  type: integer
                  minimum: 0
                  exclusiveMinimum: true
                  maximum: 2147483647
              required:
                - id
                - version
              additionalProperties: false
            endpoints:
              type: object
              additionalProperties:
                anyOf:
                  - type: string
                  - type: number
                  - type: boolean
            configuration:
              type: object
              additionalProperties:
                anyOf:
                  - type: string
                  - type: number
                  - type: boolean
            authentication:
              type: object
              properties:
                method:
                  type: string
                  enum:
                    - none
                    - bearer_token
                    - api_key
                    - basic_auth
                credentials:
                  default: []
                  maxItems: 8
                  type: array
                  items:
                    type: object
                    properties:
                      fieldKey:
                        type: string
                        minLength: 1
                        maxLength: 128
                        pattern: ^[a-z][a-z0-9_-]*$
                      secret:
                        type: string
                        minLength: 1
                        maxLength: 16384
                    required:
                      - fieldKey
                      - secret
                    additionalProperties: false
              required:
                - method
              additionalProperties: false
          required:
            - contract
            - endpoints
            - configuration
            - authentication
          additionalProperties: false
      required:
        - token
        - connection
    ProviderClientReferralSourceCreation:
      type: object
      properties:
        referralUid:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        source:
          type: object
          properties:
            inventorySourceId:
              type: string
              pattern: ^[1-9][0-9]*$
            sourceId:
              type: string
            name:
              type: string
            endpointUrl:
              nullable: true
              type: string
              format: uri
            status:
              type: string
              enum:
                - PENDING
                - ACTIVE
                - DISABLED
            authConfigured:
              type: boolean
          required:
            - inventorySourceId
            - sourceId
            - name
            - endpointUrl
            - status
            - authConfigured
          additionalProperties: false
      required:
        - referralUid
        - source
      additionalProperties: false
    ErrorResponse:
      type: object
      properties:
        data:
          type: string
          nullable: true
          enum:
            - null
        error:
          $ref: '#/components/schemas/ApiError'
      required:
        - data
        - error
      additionalProperties: false
      description: Standard error response
    ApiError:
      type: object
      properties:
        code:
          type: string
          description: Machine-readable error code
        message:
          type: string
          description: Human-readable error message
        field:
          description: Field path associated with the error
          type: string
        details:
          description: Additional error context
          type: object
          additionalProperties: {}
      required:
        - code
        - message
      additionalProperties: false
      description: Structured error object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key or access token

````