Sign-in
Apps sign in to the Geniffy MCP server with OAuth 2.1, following the MCP authorization specification. Any MCP client that supports remote servers does all of this by itself; this page is for anyone building a client or reviewing one.
The flow
Discovery
A request without a token gets 401 and a WWW-Authenticate header naming the protected-resource metadata
(RFC 9728). That points to Geniffy's authorization server metadata (RFC 8414).
GET https://api.geniffy.com/.well-known/oauth-protected-resource/mcp
GET https://api.geniffy.com/.well-known/oauth-authorization-serverRegistration
The app registers itself (RFC 7591) at POST /oauth/register. Any app may register: registering grants
nothing, only the person's approval does. Redirect addresses must be https, a loopback address on http
(localhost or 127.0.0.1, on any port), or the app's own scheme, such as cursor://.
Authorization
The app sends the person to GET /oauth/authorize with PKCE. Only S256 is accepted, and a request without a
code challenge is refused. Geniffy checks the app and the address it will send the person back to, then hands
the person to the Geniffy app to sign in.
Approval
The Geniffy app shows who is asking and where they will be sent back, and the person chooses whether the app
may only read, or also save, correct and forget. An app is named by where it sends people back: an app that
returns to claude.ai is shown as Claude, and any other app is shown under the name it gave, with a warning.
Nothing is granted until the person presses Allow.
Tokens
The app trades the one-time code for tokens at POST /oauth/token, with the PKCE verifier. The code works
once, and only for a short while. The answer carries the iss parameter (RFC 9207) on the way back.
Scopes
| Scope | Lets the app |
|---|---|
memory:read |
Search, fetch, ask, profile and list memories |
memory:write |
Also remember, correct and forget |
An app that asks for neither, or only for scopes of its own, is offered both, and the person chooses on the approval screen. Writing always includes reading.
Tokens
| Token | Lasts | |
|---|---|---|
| Access token | One hour | Sent as Authorization: Bearer gnf_at_... |
| Refresh token | Until unused for 90 days | Replaced by a new one every time it is used |
A refresh token used a second time can only be a stolen copy, so it ends the whole connection, and so does an authorization code used twice. Tokens are good for the MCP server alone, and Geniffy keeps only their SHA-256 hashes.
Revoking
- The person disconnects an app in the Geniffy app under Agents and MCP. It stops at once.
- The app revokes either token at
POST /oauth/revoke(RFC 7009), which ends the connection. - Connecting again replaces the app's previous connection rather than adding a second one.
What a connection reaches
A connection reaches its owner's own memory and nothing else: not another person's, and not the spaces an app built on the API keeps for its users. Only accounts that are open in Geniffy can connect. Every call is recorded under Requests with the app's name, and your memory stays in India.
Clients
| Method | Supported |
|---|---|
Public clients (token_endpoint_auth_method: none) |
Yes, with PKCE |
client_secret_basic, client_secret_post |
Yes |
| Grant types | authorization_code, refresh_token |