Register your MCP client through OAuth to receive a scoped token
Two supported paths lead to the same credential — a bearer MCP access token that only the MCP endpoint accepts. Issue one yourself from the dashboard, or let your client run the built-in OAuth authorization-code flow.
Path A — dashboard token#
Open Integrations → MCP access (screenshot below). The MCP server access panel's New token button opens the New MCP token modal: a Label (required, up to 100 characters — e.g. Claude Desktop) and the checkbox Allow this token to propose mutations (create pending redirect-rule drafts). On creation a Copy this token now modal shows the mcp_… value once — it is stored hashed and never shown again (the table keeps only a preview). The tokens table lists Label, Token, Status (Active/Revoked), Mutations (Read-only or Read + propose changes), Last used, and Actions (Rotate, Revoke). Limits: at most 20 active tokens per tenant, and the feature must be enabled on your plan (MCP server access is not included in the current plan. otherwise). Empty state: No MCP tokens yet. Create one to connect an AI tool to this tenant's data.
Path B — OAuth flow#
- Register the client:
POST {api}/v1/mcp/oauth/registerwith{ "redirect_uris": ["https://…"], "client_name": "Claude Desktop" }— at least one https URI (At least one https redirect_uri is required.) — and receive aclient_id(mcpc_…) withtoken_endpoint_auth_method: "none". Discovery lives at/.well-known/oauth-protected-resourceand/.well-known/oauth-authorization-server(authorization endpoint{app}/authorize, token endpoint{api}/v1/mcp/oauth/token, PKCES256only,authorization_codegrant only). - Send the user to authorize:
/authorize?client_id=…&redirect_uri=…&code_challenge=…&code_challenge_method=S256&state=…. The consent screen reads<client> wants to access Weboptiva, showsSigned in as you@company.com (Workspace), explains the client will read domains, audits, analytics, security events, and RUM regressions, and offers the checkboxAlso allow it to propose changes (create pending redirect-rule drafts) — still requires your approval to deploy. Missing or malformed parameters land onCan't continue.Denyredirects back witherror=access_denied. - Exchange the code:
Allow accessredirects with acode, which you trade atPOST /v1/mcp/oauth/token(grant_type=authorization_code,code,code_verifier) for{ access_token, token_type: "bearer", scope }— scope ismcp:readormcp:read mcp:writedepending on the checkbox. Failures answerinvalid_grant.
Using it#
Send Authorization: Bearer <access_token> to POST {api}/v1/mcp. The server only accepts MCP tokens — a missing header answers Missing bearer MCP access token. and a bad or revoked one Invalid or revoked MCP access token. Your tenant API key is never accepted here, which is what keeps the AI-facing credential separately revocable.

