Skip to main content
This page is for people building an MCP client. Pomerado’s MCPs follow the MCP authorization specification: a client discovers the authorization server from the MCP’s protected resource metadata.

Discover and sign in

1

Get the challenge

Send an MCP request without credentials, or with an expired token. The MCP answers 401 with a WWW-Authenticate header that names resource_metadata.
2

Read the metadata

Fetch that URL. It needs no credentials.
3

Authorize

Use the authorization server the metadata names. It supports dynamic client registration and client ID metadata documents. Request the token for the exact resource value.
4

Call the MCP

Send the token as Authorization: Bearer on every POST to the MCP URL.
An integration MCP’s metadata is at /.well-known/oauth-protected-resource/mcp/integrations/{integration_id} on the same host.

Rules

  • Read the authorization server from the metadata. Don’t hard-code it.
  • Use the MCP URL exactly, without a trailing slash or query string.
  • Each MCP is its own resource. See permissions for where a token works.
  • A 403 whose WWW-Authenticate header has error="insufficient_scope" means the credential isn’t allowed here. Request any scope the challenge names.
  • The MCP takes POST only. A request with an Origin header must come from an allowed origin.
  • A URL ending in /keyless never sends the challenge. A client there signs in with sign_in or connects to the signed-in URL.
A client may also skip OAuth and send an API key as the bearer token. See API keys.