Authentication · FAQ
How does a client discover Casafari's authorization server?
A client discovers it in two hops: the WWW-Authenticate header on a 401 response points to the protected resource metadata at https://mcp.casafari.com/.well-known/oauth-protected-resource, and that document points to the authorization server at https://api.casafari.com/.well-known/oauth-authorization-server.
- Read the protected resource metadata for
resource,authorization_servers,scopes_supported(intentionally empty) andresource_documentation.resourceis the server's canonical URL. Send it as theresourceparameter in every authorization and token request, because tokens are bound to it as their audience. - Read the authorization server metadata for
registration_endpoint,authorization_endpointandtoken_endpoint. Take the supported grant types, code challenge methods and auth methods from this metadata, not from a guide.
Read the live documents, not a copy. A token minted without resource has no audience, and the server rejects it.
See: Authentication and casafari.com/auth.md.