> ## Documentation Index
> Fetch the complete documentation index at: https://help.fanaura.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How assistants sign in to Fanaura with OAuth 2.1, PKCE, and dynamic client registration, and how to switch or revoke access.

Fanaura uses OAuth so you never paste a password or API key into an assistant. You sign in on a Fanaura page, choose **Allow access**, and the assistant receives a token that works only for your account.

```mermaid theme={null}
sequenceDiagram
  participant A as Assistant
  participant F as app.fanaura.com
  participant U as You
  A->>F: POST /mcp (no token)
  F-->>A: 401, WWW-Authenticate: Bearer realm="fanaura-mcp"
  A->>F: GET /.well-known/oauth-protected-resource
  A->>F: GET /.well-known/oauth-authorization-server
  A->>F: POST /api/oauth/mcp/register (redirect URI)
  F-->>A: client_id
  A->>U: Open /oauth/mcp/authorize (PKCE S256)
  U->>F: Sign in and tap Allow access
  F-->>A: Redirect with a one-time code
  A->>F: POST /api/oauth/mcp/token (code + verifier)
  F-->>A: access_token, refresh_token
  A->>F: POST /mcp with Authorization: Bearer
```

## Endpoints

| Purpose | URL |
| - | - |
| MCP server | `https://app.fanaura.com/mcp` |
| Protected resource metadata | `https://app.fanaura.com/.well-known/oauth-protected-resource` |
| Authorization server metadata | `https://app.fanaura.com/.well-known/oauth-authorization-server` |
| Issuer | `https://app.fanaura.com` |
| Authorize | `https://app.fanaura.com/oauth/mcp/authorize` |
| Token | `https://app.fanaura.com/api/oauth/mcp/token` |
| Dynamic client registration | `https://app.fanaura.com/api/oauth/mcp/register` |
| Revoke | `https://app.fanaura.com/api/oauth/mcp/revoke` |

## What Fanaura supports

<CardGroup cols={2}>
  <Card title="Grant types" icon="repeat">
    `authorization_code` and `refresh_token`.
  </Card>

  <Card title="PKCE" icon="lock">
    `S256` code challenges.
  </Card>

  <Card title="Client authentication" icon="id-card">
    `client_secret_post`, or `none` for public clients such as desktop apps.
  </Card>

  <Card title="Bearer tokens" icon="ticket">
    Sent in the `Authorization` header only.
  </Card>
</CardGroup>

## Return addresses

Desktop apps may use a loopback redirect on `localhost`, `127.0.0.1`, or `::1`. HTTPS redirects are allowed for `chatgpt.com`, `openai.com`, `claude.ai`, `anthropic.com`, `cursor.com`, and `vscode.dev`, including their subdomains. The full table is on the [developer tools page](/mcp-server/connect/developer-tools#allowed-return-addresses).

## Scopes

When an assistant asks for no scopes, Fanaura grants all three. Scopes it does not recognize are dropped. Every connection today uses all three, and the consent page lists what they allow.

| Scope | Covers |
| - | - |
| `journeys:read` | List journeys, get a journey, check links, validate publish, and read setup status |
| `journeys:write` | Create, edit, and publish journeys |
| `audience:read` | Read totals, contacts, timelines, and audience activity |

## Token lifetimes

<Columns cols={3}>
  <Card title="Authorization code" icon="timer">
    10 minutes, single use.
  </Card>

  <Card title="Access token" icon="clock">
    1 hour. The assistant refreshes it for you.
  </Card>

  <Card title="Refresh token" icon="calendar-clock">
    30 days. The assistant asks you to sign in again after that.
  </Card>
</Columns>

## The sign-in page

<Steps>
  <Step title="Sign in">
    Enter your email and tap **Send sign-in code**, then enter the code. You can tap **Use password instead**.
  </Step>

  <Step title="Check the account">
    Once signed in, the page reads "Signed in as" followed by your email, and lists what the assistant can do.
  </Step>

  <Step title="Allow or cancel">
    Tap **Allow access** to connect, **Cancel** to stop, or **Use a different account** to sign out and choose another.
  </Step>
</Steps>

<Note>
  If the page reads **Connection request invalid**, it was opened without the details an assistant sends. Start the connection from your assistant. If it reads **Connection not allowed**, the assistant's return address is not on Fanaura's list. Read [allowed return addresses](/mcp-server/connect/developer-tools#allowed-return-addresses).
</Note>

## Revoke access

<Tabs>
  <Tab title="From your assistant">
    Disconnect or remove Fanaura in the assistant's connector settings. The assistant forgets its token. Some assistants also call the revoke endpoint. If you want the token cancelled on Fanaura's side too, use one of the other two options.
  </Tab>

  <Tab title="From Fanaura support">
    Email [support@fanaura.com](mailto:support@fanaura.com) and name the assistant. Fanaura cancels its tokens. The next request from that assistant gets `401`.
  </Tab>

  <Tab title="From code">
    ```bash theme={null}
    curl -X POST https://app.fanaura.com/api/oauth/mcp/revoke \
      -d "token=YOUR_REFRESH_OR_ACCESS_TOKEN" \
      -d "client_id=YOUR_CLIENT_ID"
    ```

    Confidential clients also send `client_secret`. Fanaura answers `200` even when the token is unknown or already revoked.
  </Tab>
</Tabs>

<Warning>
  Signing out of Fanaura in your browser does not disconnect an assistant. Its token stays valid until it expires or is revoked.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.