# auth.md

You are an agent. This host is the GetAccept MCP resource server and its OAuth 2.1 authorization server.

- Resource: `https://mcp.getaccept.com/mcp`
- Authorization server: `https://mcp.getaccept.com`

Registration is RFC 7591 dynamic client registration, then authorization-code + PKCE. There is no `/agent/identity` endpoint. Treat `/.well-known/oauth-protected-resource` as authoritative if anything here conflicts with it.

## 1. Discover

An unauthenticated call to `/mcp` returns:

```http
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer resource_metadata="https://mcp.getaccept.com/.well-known/oauth-protected-resource"
```

Fetch the Protected Resource Metadata, then the Authorization Server metadata:

```http
GET https://mcp.getaccept.com/.well-known/oauth-protected-resource
GET https://mcp.getaccept.com/.well-known/oauth-authorization-server
```

Read `resource`, `authorization_servers`, `scopes_supported` (`basic`), `bearer_methods_supported` (`header`), `issuer`, `authorization_endpoint`, `token_endpoint`, `registration_endpoint`, and `agent_auth`.

`agent_auth.register_uri` is `https://mcp.getaccept.com/register`. `agent_auth.skill` is this document. `identity_types_supported` is `anonymous` — the user signs in at GetAccept during `/authorize`; the MCP client itself has no prior identity.

## 2. Register

```http
POST https://mcp.getaccept.com/register
Content-Type: application/json

{
  "redirect_uris": ["https://your-client.example/callback"],
  "client_name": "Your Agent"
}
```

Clients registered here are public (`token_endpoint_auth_method` is `none`). Save `client_id`.

## 3. Authorize

Send the user to `authorization_endpoint` with `response_type=code`, PKCE `S256`, `client_id`, `redirect_uri`, and `scope=basic`. They sign in to GetAccept and approve consent. The callback returns `code`.

## 4. Token

```http
POST https://mcp.getaccept.com/token
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code
&code=<code>
&redirect_uri=<redirect_uri>
&client_id=<client_id>
&code_verifier=<pkce_verifier>
```

`refresh_token` is also supported. Present the access token as `Authorization: Bearer` on `https://mcp.getaccept.com/mcp`.

## 5. Use

Streamable HTTP MCP at `https://mcp.getaccept.com/mcp`. Disconnect the connector in the MCP client to drop access. Human docs: https://mcp.getaccept.com/docs.
