Skip to main content
Proofable MCP uses the Authorization Code grant. The user signs in on Proofable with the same passkey or wallet flow as the product.
Default: add https://mcp.proofable.me/mcp and finish the sign-in your client opens. Only Claude connectors and Devin render a control called Connect. Optional terminal installer: npx -y @proofable/sdk setup. Use this page for custom MCP hosts, security review, standalone sign-in, or raw HTTP integration.

Flow overview

/oauth/authorize validates OAuth parameters. Without a session it redirects to https://proofable.me/verify?intent=mcp&returnTo=/oauth/authorize?.... After login it issues a single-use code (10-minute TTL) and redirects to redirect_uri. Repeated identical resource values are accepted (RFC 8707). Token exchange and revocation are public OAuth endpoints on proofable.me.

Discovery

Protected resource metadata

https://mcp.proofable.me/mcp is the single endpoint: an uncredentialed request, including initialize, returns 401 + WWW-Authenticate, so interactive installs start DCR + PKCE immediately. A server key uses the same URL as a Bearer token. Protected operations return the same challenge:
The 401 + WWW-Authenticate response is served for every method without a token, on the same single endpoint, so interactive installs start DCR + PKCE immediately and server keys connect to the same URL.

Authorization server metadata

Authorization

The example below shows the Proofable SDK CLI loopback flow (proofable auth --oauth), which identifies as proofable-cli. Host MCP clients use the same endpoint with the client_id issued to them by DCR and their own loopback redirect_uri. Never use proofable-cli for host clients.

Token exchange

Response:

Refresh tokens

Refresh tokens rotate on each use. Include offline_access in the initial scope to receive one.

Token claims

The MCP access token is a JWT: OAuth access tokens are valid only when aud is https://mcp.proofable.me/mcp, iss is https://proofable.me, token_use is mcp_access, and the token is not expired or revoked.

Scope model

These four scopes are the complete public permission model. Server keys (npk_*) are a full-profile credential.

Revocation

Revoking an access token also invalidates all associated refresh tokens.

Registered clients

Hosted MCP clients use a URL-only MCP config. The host discovers OAuth metadata via /.well-known/oauth-protected-resource, runs its own Dynamic Client Registration (DCR) against /oauth/register, and owns its PKCE + silent-refresh lifecycle. DCR issues neus-mcp-host for non-loopback redirect URIs. Do not pin proofable-cli for host-owned OAuth. The OAuth examples above show client_id=proofable-cli because they document the CLI loopback path (proofable auth --oauth). Host clients receive their own client_id from DCR and send that instead, plus the same resource=https://mcp.proofable.me/mcp.

Security properties

Auth

Keys and headers.

Setup

Install and configure.

Endpoints

Discovery URLs.
Last modified on October 5, 2026