Endpoints
What Fanaura supports
Grant types
authorization_code and refresh_token.PKCE
S256 code challenges.Client authentication
client_secret_post, or none for public clients such as desktop apps.Bearer tokens
Sent in the
Authorization header only.Return addresses
Desktop apps may use a loopback redirect onlocalhost, 127.0.0.1, or ::1. HTTPS redirects are allowed for chatgpt.com, openai.com, claude.ai, anthropic.com, cursor.com, and vscode.dev, including their subdomains. The full table is on the developer tools page.
Scopes
When an assistant asks for no scopes, Fanaura grants all three. Scopes it does not recognize are dropped. Every connection today uses all three, and the consent page lists what they allow.Token lifetimes
Authorization code
10 minutes, single use.
Access token
1 hour. The assistant refreshes it for you.
Refresh token
30 days. The assistant asks you to sign in again after that.
The sign-in page
1
Sign in
Enter your email and tap Send sign-in code, then enter the code. You can tap Use password instead.
2
Check the account
Once signed in, the page reads “Signed in as” followed by your email, and lists what the assistant can do.
3
Allow or cancel
Tap Allow access to connect, Cancel to stop, or Use a different account to sign out and choose another.
If the page reads Connection request invalid, it was opened without the details an assistant sends. Start the connection from your assistant. If it reads Connection not allowed, the assistant’s return address is not on Fanaura’s list. Read allowed return addresses.
Revoke access
- From your assistant
- From Fanaura support
- From code
Disconnect or remove Fanaura in the assistant’s connector settings. The assistant forgets its token. Some assistants also call the revoke endpoint. If you want the token cancelled on Fanaura’s side too, use one of the other two options.

