GeniffyDocs
Log In Get a key

Sign-in

Apps sign in to the Geniffy MCP server with OAuth 2.1, following the MCP authorization specification. Any MCP client that supports remote servers does all of this by itself; this page is for anyone building a client or reviewing one.

The flow

1

Discovery

A request without a token gets 401 and a WWW-Authenticate header naming the protected-resource metadata (RFC 9728). That points to Geniffy's authorization server metadata (RFC 8414).

GET  https://api.geniffy.com/.well-known/oauth-protected-resource/mcp
GET  https://api.geniffy.com/.well-known/oauth-authorization-server
2

Registration

The app registers itself (RFC 7591) at POST /oauth/register. Any app may register: registering grants nothing, only the person's approval does. Redirect addresses must be https, a loopback address on http (localhost or 127.0.0.1, on any port), or the app's own scheme, such as cursor://.

3

Authorization

The app sends the person to GET /oauth/authorize with PKCE. Only S256 is accepted, and a request without a code challenge is refused. Geniffy checks the app and the address it will send the person back to, then hands the person to the Geniffy app to sign in.

4

Approval

The Geniffy app shows who is asking and where they will be sent back, and the person chooses whether the app may only read, or also save, correct and forget. An app is named by where it sends people back: an app that returns to claude.ai is shown as Claude, and any other app is shown under the name it gave, with a warning. Nothing is granted until the person presses Allow.

5

Tokens

The app trades the one-time code for tokens at POST /oauth/token, with the PKCE verifier. The code works once, and only for a short while. The answer carries the iss parameter (RFC 9207) on the way back.

Scopes

Scope Lets the app
memory:read Search, fetch, ask, profile and list memories
memory:write Also remember, correct and forget

An app that asks for neither, or only for scopes of its own, is offered both, and the person chooses on the approval screen. Writing always includes reading.

Tokens

Token Lasts
Access token One hour Sent as Authorization: Bearer gnf_at_...
Refresh token Until unused for 90 days Replaced by a new one every time it is used

A refresh token used a second time can only be a stolen copy, so it ends the whole connection, and so does an authorization code used twice. Tokens are good for the MCP server alone, and Geniffy keeps only their SHA-256 hashes.

Revoking

  • The person disconnects an app in the Geniffy app under Agents and MCP. It stops at once.
  • The app revokes either token at POST /oauth/revoke (RFC 7009), which ends the connection.
  • Connecting again replaces the app's previous connection rather than adding a second one.

What a connection reaches

A connection reaches its owner's own memory and nothing else: not another person's, and not the spaces an app built on the API keeps for its users. Only accounts that are open in Geniffy can connect. Every call is recorded under Requests with the app's name, and your memory stays in India.

Clients

Method Supported
Public clients (token_endpoint_auth_method: none) Yes, with PKCE
client_secret_basic, client_secret_post Yes
Grant types authorization_code, refresh_token
Last updated October 5, 2026