Authentication · FAQ
Can my MCP client register itself with Casafari?
Yes, a client that acts for a signed-in person can register itself once at the registration endpoint; a client with no person to sign in cannot, and uses credentials Casafari issues instead.
Send a POST with client_name, your redirect_uris, grant_types set to ["authorization_code", "refresh_token"], and token_endpoint_auth_method set to none. Each redirect URI must use https, http on a loopback host, or a private-use scheme, and must not include a fragment. Any other grant type, redirect URI, or auth method is rejected with 400 invalid_client_metadata, so never request client_credentials there. The 201 response contains the client_id. Store it and don't register again. A public client has no secret and authenticates with PKCE (S256).
See: Authentication and casafari.com/auth.md.