1. Verify the credential
2. Discover applications
authenticationMethods, each with an authenticationId and field list) and whether it supports object selection:
3. Create a connection
Direct credentials (API-key/DB style methods) - one call:requiresOAuthSignIn: true) - three steps:
4. Discover tools and read a contract
5. Execute
?connectionId= to use your default connection; pass ?toolsetId= to scope resolution to a toolset. Full semantics: API overview.