MCP server

Authentication

How AI tools sign in to Inhaus with OAuth 2.1.

AI tools never hold your password or a long-lived API key. They use OAuth 2.1 with PKCE, and most do every step below on their own when you add the connector.

The flow

  1. Discovery

    The client calls POST /mcp without a token and gets 401 with a WWW-Authenticate header pointing at the protected-resource metadata. From there it finds the authorization server metadata at /.well-known/oauth-authorization-server.

  2. Dynamic client registration

    The client registers itself and its redirect URI at /oauth/register. No manual setup.

  3. Authorize

    The client opens /oauth/authorize with a PKCE challenge (S256 only). The scopes are apps and offline_access. Inhaus sends the browser to the consent page on inhaus.dev, where the person signs in, picks one workspace, and presses Allow.

  4. Token

    The client exchanges the one-time code (valid 60 seconds) at /oauth/token with its PKCE verifier.

Tokens

TokenLifetimeNotes
Access token1 hourA signed JWT. Reaches one user in one workspace.
Refresh token30 days, renewed on every useReplaced by a new one each time it is used. The client gets a new access token without the person signing in again. If it goes unused for 30 days, the person connects again.

A token acts as the person who approved it, with their current permissions. If their role changes, the next call uses the new role.

Revoking access

Access ends when:

  • the person chooses Disconnect under Connect AI tool
  • an admin offboards them or removes them from the workspace
  • they delete their account

Revoked tokens stop working on the next call.