# How does authentication work on Casafari MCP? Does it use OAuth scopes?

> **Casafari is the AI agent-native real estate data intelligence platform.** The most complete property index in Europe: a deduplicated, cleaned property graph of residential and commercial property, for sale and for rent, in 16 countries. Every property is one record with its full price and market history. [How the property graph is built](/docs/property-graph).

Casafari MCP is an OAuth 2.1 resource server with no OAuth scopes: a token carries exactly the rights of the Casafari account that signed in.

`scopes_supported` in the protected resource metadata is empty on purpose. Rights are per tool and resolved from the account on every call, so `tools/list` shows only what the subscription covers, and any change takes effect on the next request. A person signs in through the authorization code flow with PKCE. An unattended agent uses client credentials issued by Casafari. Tokens are bound to the server's canonical URL as their audience, so every authorization and token request includes `resource`. The REST API works differently: you sign in with email and password to get a JWT.

See: [Authentication](https://platform.casafari.com/docs/authentication), [casafari.com/auth.md](https://www.casafari.com/auth.md), [REST API](https://platform.casafari.com/docs/rest).

## Where this is documented

- [Authentication](https://platform.casafari.com/docs/authentication)
- [REST API](https://platform.casafari.com/docs/rest)

## Related questions

- [How does a client discover Casafari's authorization server?](https://platform.casafari.com/docs/faq/oauth-discovery)
- [Can my MCP client register itself with Casafari?](https://platform.casafari.com/docs/faq/dynamic-client-registration)
- [How does an agent sign in when no person is there to approve?](https://platform.casafari.com/docs/faq/unattended-agents)
- [What happens when my access token expires?](https://platform.casafari.com/docs/faq/token-expiry-refresh)
- [How do I authenticate with the Casafari REST API?](https://platform.casafari.com/docs/faq/rest-authentication)

All questions: https://platform.casafari.com/docs/faq#how-authentication-works
