# How does a client discover Casafari's authorization server?

> **Casafari is the AI agent-native real estate data intelligence platform.** The most complete property index in Europe: a deduplicated, cleaned property graph of residential and commercial property, for sale and for rent, in 16 countries. Every property is one record with its full price and market history. [How the property graph is built](/docs/property-graph).

A client discovers it in two hops: the `WWW-Authenticate` header on a `401` response points to the protected resource metadata at `https://mcp.casafari.com/.well-known/oauth-protected-resource`, and that document points to the authorization server at `https://api.casafari.com/.well-known/oauth-authorization-server`.

1. Read the protected resource metadata for `resource`, `authorization_servers`, `scopes_supported` (intentionally empty) and `resource_documentation`. `resource` is the server's canonical URL. Send it as the `resource` parameter in every authorization and token request, because tokens are bound to it as their audience.
2. Read the authorization server metadata for `registration_endpoint`, `authorization_endpoint` and `token_endpoint`. Take the supported grant types, code challenge methods and auth methods from this metadata, not from a guide.

Read the live documents, not a copy. A token minted without `resource` has no audience, and the server rejects it.

See: [Authentication](https://platform.casafari.com/docs/authentication) and [casafari.com/auth.md](https://www.casafari.com/auth.md).

## Where this is documented

- [Authentication](https://platform.casafari.com/docs/authentication)

## Related questions

- [How does authentication work on Casafari MCP? Does it use OAuth scopes?](https://platform.casafari.com/docs/faq/how-authentication-works)
- [Can my MCP client register itself with Casafari?](https://platform.casafari.com/docs/faq/dynamic-client-registration)
- [How does an agent sign in when no person is there to approve?](https://platform.casafari.com/docs/faq/unattended-agents)
- [What happens when my access token expires?](https://platform.casafari.com/docs/faq/token-expiry-refresh)
- [How do I authenticate with the Casafari REST API?](https://platform.casafari.com/docs/faq/rest-authentication)

All questions: https://platform.casafari.com/docs/faq#oauth-discovery
