MCP authentication and OAuth

MCP connections authenticate with OAuth 2.1 in your browser over Streamable HTTP. No Developer API key and no Spotify credentials are required: your AI client never sees your artist.tools or Spotify password.

Client registration

Client ID Metadata Documents are the preferred registration path. A client publishes its metadata at an HTTPS URL and presents that URL as its client_id; the authorization server fetches and validates the document during authorization. The server advertises this support as client_id_metadata_document_supported: true in its authorization-server metadata.

Dynamic Client Registration is the compatibility fallback for clients that cannot publish a metadata document. The client posts its metadata to /oauth/register and receives a registered client ID. Registration accepts one to ten redirect URIs, which must use HTTPS, loopback HTTP, or a private-use URI scheme.

Endpoint and transport

The MCP server is served over Streamable HTTP at the /mcp path and requires a Bearer token. The Server URL shown in Settings > Integrations is your app origin followed by /mcp.

Discovery metadata is served at /.well-known/oauth-protected-resource/mcp and /.well-known/oauth-authorization-server.

OAuth flow

The only supported scope is mcp. Authorization requires S256 PKCE and these endpoints:

  • /oauth/authorize — the consent screen

  • /oauth/token — authorization-code and refresh-token exchange

  • /oauth/revoke — revoke a connection

  • /oauth/register — dynamic client registration (compatibility fallback)

Authorization requires signing in to your artist.tools account in the browser. The consent screen shows the requesting client and the requested access; choose Authorize or Deny. Denying the request redirects the client with an access_denied error.

A connection can also request administrator access, which is granted only to current administrators. See Connect artist.tools to an MCP client for what this unlocks.

Token lifetimes

Authorization codes expire after 10 minutes and are single-use. Access tokens last 1 hour. Refresh tokens last 90 days when the client supports them and are rotated on refresh.

Revocation

Disconnecting a client from Settings > Integrations, or revoking its tokens, removes its active connection immediately and invalidates its access and refresh tokens.

Errors

Requests without a Bearer token return 401 with "This is an authenticated MCP endpoint. Add this URL to an MCP client; OAuth will start automatically." Invalid or expired tokens return 401 with "The access token is invalid or expired. Reauthorize this MCP server."

Was this helpful?