viralshooterDocs

Authentication

How an MCP client finds the sign-in server and gets a token.

viralshooter uses OAuth 2.1 with PKCE. Users sign in with their viralshooter account (Google) and approve the app on a consent screen. Clients never handle a password or an API key.

Discovery

  1. A request to https://mcp-staging.viralshooter.com/mcp without a token returns 401 with WWW-Authenticate: Bearer resource_metadata="…/.well-known/oauth-protected-resource/mcp".
  2. The protected-resource metadata (RFC 9728) names the authorization server: https://staging.viralshooter.com/api/auth.
  3. The authorization server's metadata (RFC 8414) is at /.well-known/oauth-authorization-server/api/auth on the same host.

Registration

Dynamic client registration (RFC 7591) at https://staging.viralshooter.com/api/auth/oauth2/register, for public clients (token_endpoint_auth_method: none). A client that registers only loopback http redirect URIs is treated as a native app (RFC 8252). There is no client ID to enter by hand.

Tokens

Code challengeS256
Scopesopenid, profile, email, offline_access
Access tokenA signed JWT, valid 1 hour, audience = the server URL. Checked against the server's JWKS
Refresh tokenIssued with offline_access. Valid 30 days, rotates on use; a just-used one is still accepted for 30 seconds

Disconnecting

A user can disconnect an app in Settings → AI agents. Its next call is refused with 401 and error="invalid_token", even if its access token has not expired, and its refresh tokens stop working.

On this page