# Create an MCP service user credential

Launch stage: Beta

`POST /api/2.1/unity-catalog/{name=mcp-services/*}/user-credentials`

Logs the caller in to an MCP service: creates their per-user OAuth credential, or
 re-authenticates it if one already exists. The request body carries the OAuth exchange fields.

 You must be the owner of the MCP service or have `EXECUTE` on it, plus `USE_CATALOG` on the
 parent catalog and `USE_SCHEMA` on the parent schema.

API scopes: unity-catalog

## Path parameters

- `name` (string, required)
  Resource name of the MCP service.
   Format: `mcp-services/{catalog}.{schema}.{mcp_service}`.

## Request body

- `options` (object, optional)
  OAuth exchange fields: `pkce_verifier`, `authorization_code`, and `oauth_redirect_uri`.

## Returns

- `options` (object, optional, Output only)
  Token-expiry info for the credential, returned as a flat map: `access_token_expiration` (always
   set) and `refresh_token_expiration` (set when the credential has a refresh token). Both values
   are timestamps.
- `provisioning_info` (object, optional, Output only)
  Provisioning state of the credential. `ACTIVE` means the caller is logged in and the credential
   is usable; any other state means the login has not completed.
  - `state` (string, optional)
    The provisioning state of the resource.
    Possible values:
    - `STATE_UNSPECIFIED`
    - `PROVISIONING`
    - `ACTIVE`
    - `FAILED`
    - `DELETING`
    - `UPDATING`
    - `DEGRADED`

## Response

```json
{
  "options": {},
  "provisioning_info": {
    "state": "PROVISIONING"
  }
}
```

