Discover and sign in
1
Get the challenge
Send an MCP request without credentials, or with an expired token. The MCP answers
401 with a WWW-Authenticate header that names resource_metadata.2
Read the metadata
Fetch that URL. It needs no credentials.
3
Authorize
Use the authorization server the metadata names. It supports dynamic client registration and client ID metadata documents. Request the token for the exact
resource value.4
Call the MCP
Send the token as
Authorization: Bearer on every POST to the MCP URL.
An integration MCP’s metadata is at
/.well-known/oauth-protected-resource/mcp/integrations/{integration_id} on the same host.
Rules
- Read the authorization server from the metadata. Don’t hard-code it.
- Use the MCP URL exactly, without a trailing slash or query string.
- Each MCP is its own resource. See permissions for where a token works.
- A
403whoseWWW-Authenticateheader haserror="insufficient_scope"means the credential isn’t allowed here. Request anyscopethe challenge names. - The MCP takes
POSTonly. A request with anOriginheader must come from an allowed origin. - A URL ending in
/keylessnever sends the challenge. A client there signs in withsign_inor connects to the signed-in URL.