MCP authentication and OAuth
MCP connections authenticate with OAuth 2.1 in your browser over Streamable HTTP. No Developer API key and no Spotify credentials are required: your AI client never sees your artist.tools or Spotify password.
Client registration
Client ID Metadata Documents are the preferred registration path. A client publishes its metadata at an HTTPS URL and presents that URL as its client_id; the authorization server fetches and validates the document during authorization. The server advertises this support as client_id_metadata_document_supported: true in its authorization-server metadata.
Dynamic Client Registration is the compatibility fallback for clients that cannot publish a metadata document. The client posts its metadata to /oauth/register and receives a registered client ID. Registration accepts one to ten redirect URIs, which must use HTTPS, loopback HTTP, or a private-use URI scheme.
Endpoint and transport
The MCP server is served over Streamable HTTP at the /mcp path and requires a Bearer token. The Server URL shown in Settings > Integrations is your app origin followed by /mcp.
Discovery metadata is served at /.well-known/oauth-protected-resource/mcp and /.well-known/oauth-authorization-server.
OAuth flow
The only supported scope is mcp. Authorization requires S256 PKCE and these endpoints:
/oauth/authorize— the consent screen/oauth/token— authorization-code and refresh-token exchange/oauth/revoke— revoke a connection/oauth/register— dynamic client registration (compatibility fallback)
Authorization requires signing in to your artist.tools account in the browser. The consent screen shows the requesting client and the requested access; choose Authorize or Deny. Denying the request redirects the client with an access_denied error.
A connection can also request administrator access, which is granted only to current administrators. See Connect artist.tools to an MCP client for what this unlocks.
Token lifetimes
Authorization codes expire after 10 minutes and are single-use. Access tokens last 1 hour. Refresh tokens last 90 days when the client supports them and are rotated on refresh.
Revocation
Disconnecting a client from Settings > Integrations, or revoking its tokens, removes its active connection immediately and invalidates its access and refresh tokens.
Errors
Requests without a Bearer token return 401 with "This is an authenticated MCP endpoint. Add this URL to an MCP client; OAuth will start automatically." Invalid or expired tokens return 401 with "The access token is invalid or expired. Reauthorize this MCP server."