Skip to main content
Fanaura uses OAuth so you never paste a password or API key into an assistant. You sign in on a Fanaura page, choose Allow access, and the assistant receives a token that works only for your account.

Endpoints

What Fanaura supports

Grant types

authorization_code and refresh_token.

PKCE

S256 code challenges.

Client authentication

client_secret_post, or none for public clients such as desktop apps.

Bearer tokens

Sent in the Authorization header only.

Return addresses

Desktop apps may use a loopback redirect on localhost, 127.0.0.1, or ::1. HTTPS redirects are allowed for chatgpt.com, openai.com, claude.ai, anthropic.com, cursor.com, and vscode.dev, including their subdomains. The full table is on the developer tools page.

Scopes

When an assistant asks for no scopes, Fanaura grants all three. Scopes it does not recognize are dropped. Every connection today uses all three, and the consent page lists what they allow.

Token lifetimes

Authorization code

10 minutes, single use.

Access token

1 hour. The assistant refreshes it for you.

Refresh token

30 days. The assistant asks you to sign in again after that.

The sign-in page

1

Sign in

Enter your email and tap Send sign-in code, then enter the code. You can tap Use password instead.
2

Check the account

Once signed in, the page reads “Signed in as” followed by your email, and lists what the assistant can do.
3

Allow or cancel

Tap Allow access to connect, Cancel to stop, or Use a different account to sign out and choose another.
If the page reads Connection request invalid, it was opened without the details an assistant sends. Start the connection from your assistant. If it reads Connection not allowed, the assistant’s return address is not on Fanaura’s list. Read allowed return addresses.

Revoke access

Disconnect or remove Fanaura in the assistant’s connector settings. The assistant forgets its token. Some assistants also call the revoke endpoint. If you want the token cancelled on Fanaura’s side too, use one of the other two options.
Signing out of Fanaura in your browser does not disconnect an assistant. Its token stays valid until it expires or is revoked.