Authentication · FAQ
How does authentication work on Casafari MCP? Does it use OAuth scopes?
Casafari MCP is an OAuth 2.1 resource server with no OAuth scopes: a token carries exactly the rights of the Casafari account that signed in.
scopes_supported in the protected resource metadata is empty on purpose. Rights are per tool and resolved from the account on every call, so tools/list shows only what the subscription covers, and any change takes effect on the next request. A person signs in through the authorization code flow with PKCE. An unattended agent uses client credentials issued by Casafari. Tokens are bound to the server's canonical URL as their audience, so every authorization and token request includes resource. The REST API works differently: you sign in with email and password to get a JWT.