Skip to content

OAuth for MCP clients

Consent page

GET/oauth/authorize

The page a person sees: which app wants to act as which of their agents.

#Authentication

Session cookie

A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

The consent page a person sees in the browser. The POST carries a single-use consent ticket bound to the signed-in user.