Authentication
How an MCP client finds the sign-in server and gets a token.
viralshooter uses OAuth 2.1 with PKCE. Users sign in with their viralshooter account (Google) and approve the app on a consent screen. Clients never handle a password or an API key.
Discovery
- A request to
https://mcp-staging.viralshooter.com/mcpwithout a token returns401withWWW-Authenticate: Bearer resource_metadata="…/.well-known/oauth-protected-resource/mcp". - The protected-resource metadata (RFC 9728) names the authorization server:
https://staging.viralshooter.com/api/auth. - The authorization server's metadata (RFC 8414) is at
/.well-known/oauth-authorization-server/api/authon the same host.
Registration
Dynamic client registration (RFC 7591) at https://staging.viralshooter.com/api/auth/oauth2/register, for public clients (token_endpoint_auth_method: none). A client that registers only loopback http redirect URIs is treated as a native app (RFC 8252). There is no client ID to enter by hand.
Tokens
| Code challenge | S256 |
| Scopes | openid, profile, email, offline_access |
| Access token | A signed JWT, valid 1 hour, audience = the server URL. Checked against the server's JWKS |
| Refresh token | Issued with offline_access. Valid 30 days, rotates on use; a just-used one is still accepted for 30 seconds |
Disconnecting
A user can disconnect an app in Settings → AI agents. Its next call is refused with 401 and error="invalid_token", even if its access token has not expired, and its refresh tokens stop working.