Default: add
https://mcp.proofable.me/mcp and finish the sign-in your client opens. Only Claude connectors and Devin render a control called Connect. Optional terminal installer: npx -y @proofable/sdk setup. Use this page for custom MCP hosts, security review, standalone sign-in, or raw HTTP integration.Flow overview
/oauth/authorize validates OAuth parameters. Without a session it redirects to https://proofable.me/verify?intent=mcp&returnTo=/oauth/authorize?.... After login it issues a single-use code (10-minute TTL) and redirects to redirect_uri. Repeated identical resource values are accepted (RFC 8707).
Token exchange and revocation are public OAuth endpoints on proofable.me.
Discovery
Protected resource metadata
https://mcp.proofable.me/mcp is the single endpoint: an uncredentialed request, including initialize, returns 401 + WWW-Authenticate, so interactive installs start DCR + PKCE immediately. A server key uses the same URL as a Bearer token. Protected operations return the same challenge:
401 + WWW-Authenticate response is served for every method without a token, on the same single endpoint, so interactive installs start DCR + PKCE immediately and server keys connect to the same URL.
Authorization server metadata
Authorization
The example below shows the Proofable SDK CLI loopback flow (proofable auth --oauth), which identifies as proofable-cli. Host MCP clients use the same endpoint with the client_id issued to them by DCR and their own loopback redirect_uri. Never use proofable-cli for host clients.
Token exchange
Refresh tokens
offline_access in the initial scope to receive one.
Token claims
The MCP access token is a JWT:
OAuth access tokens are valid only when
aud is https://mcp.proofable.me/mcp, iss is https://proofable.me, token_use is mcp_access, and the token is not expired or revoked.
Scope model
These four scopes are the complete public permission model. Server keys (
npk_*) are a full-profile credential.
Revocation
Registered clients
Hosted MCP clients use a URL-only MCP config. The host discovers OAuth metadata via
/.well-known/oauth-protected-resource, runs its own Dynamic Client Registration (DCR) against /oauth/register, and owns its PKCE + silent-refresh lifecycle. DCR issues neus-mcp-host for non-loopback redirect URIs. Do not pin proofable-cli for host-owned OAuth.
The OAuth examples above show client_id=proofable-cli because they document the CLI loopback path (proofable auth --oauth). Host clients receive their own client_id from DCR and send that instead, plus the same resource=https://mcp.proofable.me/mcp.
Security properties
Auth
Keys and headers.
Setup
Install and configure.
Endpoints
Discovery URLs.