MCP server
Authentication
How AI tools sign in to Inhaus with OAuth 2.1.
AI tools never hold your password or a long-lived API key. They use OAuth 2.1 with PKCE, and most do every step below on their own when you add the connector.
The flow
- Discovery
The client calls
POST /mcpwithout a token and gets401with aWWW-Authenticateheader pointing at the protected-resource metadata. From there it finds the authorization server metadata at/.well-known/oauth-authorization-server. - Dynamic client registration
The client registers itself and its redirect URI at
/oauth/register. No manual setup. - Authorize
The client opens
/oauth/authorizewith a PKCE challenge (S256only). The scopes areappsandoffline_access. Inhaus sends the browser to the consent page oninhaus.dev, where the person signs in, picks one workspace, and presses Allow. - Token
The client exchanges the one-time code (valid 60 seconds) at
/oauth/tokenwith its PKCE verifier.
Tokens
| Token | Lifetime | Notes |
|---|---|---|
| Access token | 1 hour | A signed JWT. Reaches one user in one workspace. |
| Refresh token | 30 days, renewed on every use | Replaced by a new one each time it is used. The client gets a new access token without the person signing in again. If it goes unused for 30 days, the person connects again. |
A token acts as the person who approved it, with their current permissions. If their role changes, the next call uses the new role.
Revoking access
Access ends when:
- the person chooses Disconnect under Connect AI tool
- an admin offboards them or removes them from the workspace
- they delete their account
Revoked tokens stop working on the next call.