Access · FAQ
Do I need an API key for Casafari MCP?
No, Casafari MCP doesn't use an API key: you sign in with OAuth 2.1 through your Casafari account, and the token you get carries that account's rights.
- Interactive clients (Claude, ChatGPT, Cursor, VS Code, Claude Code) open Casafari's sign-in page the first time you connect, so you never paste a credential.
- Your own client registers itself and uses PKCE, so it needs no secret.
- An agent with no person to approve uses a
client_idandclient_secretthat Casafari issues for the account (client credentials grant). - The REST API works differently:
POST /loginwith email and password returns a JWT access token and a refresh token.
See: Authentication and casafari.com/auth.md.