Skip to content
DocsGo to Dashboard
Use the MCP server

Register your MCP client through OAuth to receive a scoped token

Two supported paths lead to the same credential — a bearer MCP access token that only the MCP endpoint accepts. Issue one yourself from the dashboard, or let your client run the built-in OAuth authorization-code flow.

MCP access screen for registering an MCP client and issuing tokens
Register an MCP client here to obtain an access token.

Path A — dashboard token#

Open Integrations → MCP access (screenshot below). The MCP server access panel's New token button opens the New MCP token modal: a Label (required, up to 100 characters — e.g. Claude Desktop) and the checkbox Allow this token to propose mutations (create pending redirect-rule drafts). On creation a Copy this token now modal shows the mcp_… value once — it is stored hashed and never shown again (the table keeps only a preview). The tokens table lists Label, Token, Status (Active/Revoked), Mutations (Read-only or Read + propose changes), Last used, and Actions (Rotate, Revoke). Limits: at most 20 active tokens per tenant, and the feature must be enabled on your plan (MCP server access is not included in the current plan. otherwise). Empty state: No MCP tokens yet. Create one to connect an AI tool to this tenant's data.

Path B — OAuth flow#

  1. Register the client: POST {api}/v1/mcp/oauth/register with { "redirect_uris": ["https://…"], "client_name": "Claude Desktop" } — at least one https URI (At least one https redirect_uri is required.) — and receive a client_id (mcpc_…) with token_endpoint_auth_method: "none". Discovery lives at /.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server (authorization endpoint {app}/authorize, token endpoint {api}/v1/mcp/oauth/token, PKCE S256 only, authorization_code grant only).
  2. Send the user to authorize: /authorize?client_id=…&redirect_uri=…&code_challenge=…&code_challenge_method=S256&state=…. The consent screen reads <client> wants to access Weboptiva, shows Signed in as you@company.com (Workspace), explains the client will read domains, audits, analytics, security events, and RUM regressions, and offers the checkbox Also allow it to propose changes (create pending redirect-rule drafts) — still requires your approval to deploy. Missing or malformed parameters land on Can't continue. Deny redirects back with error=access_denied.
  3. Exchange the code: Allow access redirects with a code, which you trade at POST /v1/mcp/oauth/token (grant_type=authorization_code, code, code_verifier) for { access_token, token_type: "bearer", scope } — scope is mcp:read or mcp:read mcp:write depending on the checkbox. Failures answer invalid_grant.

Using it#

Send Authorization: Bearer <access_token> to POST {api}/v1/mcp. The server only accepts MCP tokens — a missing header answers Missing bearer MCP access token. and a bad or revoked one Invalid or revoked MCP access token. Your tenant API key is never accepted here, which is what keeps the AI-facing credential separately revocable.

Back to Use the MCP server