# Sign-in

> How apps sign in to the Geniffy MCP server: OAuth 2.1 with discovery, registration, PKCE, approval and revocation.

Apps sign in to the Geniffy MCP server with OAuth 2.1, following the MCP authorization specification. Any MCP
client that supports remote servers does all of this by itself; this page is for anyone building a client or
reviewing one.

## The flow

### 1. Discovery


A request without a token gets `401` and a `WWW-Authenticate` header naming the protected-resource metadata
(RFC 9728). That points to Geniffy's authorization server metadata (RFC 8414).

```text
GET  https://api.geniffy.com/.well-known/oauth-protected-resource/mcp
GET  https://api.geniffy.com/.well-known/oauth-authorization-server
```

### 2. Registration


The app registers itself (RFC 7591) at `POST /oauth/register`. Any app may register: registering grants
nothing, only the person's approval does. Redirect addresses must be `https`, a loopback address on `http`
(`localhost` or `127.0.0.1`, on any port), or the app's own scheme, such as `cursor://`.

### 3. Authorization


The app sends the person to `GET /oauth/authorize` with PKCE. Only `S256` is accepted, and a request without a
code challenge is refused. Geniffy checks the app and the address it will send the person back to, then hands
the person to the Geniffy app to sign in.

### 4. Approval


The Geniffy app shows who is asking and where they will be sent back, and the person chooses whether the app
may only read, or also save, correct and forget. An app is named by where it sends people back: an app that
returns to `claude.ai` is shown as Claude, and any other app is shown under the name it gave, with a warning.
Nothing is granted until the person presses **Allow**.

### 5. Tokens


The app trades the one-time code for tokens at `POST /oauth/token`, with the PKCE verifier. The code works
once, and only for a short while. The answer carries the `iss` parameter (RFC 9207) on the way back.


## Scopes

| Scope | Lets the app |
| --- | --- |
| `memory:read` | Search, fetch, ask, profile and list memories |
| `memory:write` | Also remember, correct and forget |

An app that asks for neither, or only for scopes of its own, is offered both, and the person chooses on the
approval screen. Writing always includes reading.

## Tokens

| Token | Lasts | |
| --- | --- | --- |
| Access token | One hour | Sent as `Authorization: Bearer gnf_at_...` |
| Refresh token | Until unused for 90 days | Replaced by a new one every time it is used |

A refresh token used a second time can only be a stolen copy, so it ends the whole connection, and so does an
authorization code used twice. Tokens are good for the MCP server alone, and Geniffy keeps only their
SHA-256 hashes.

## Revoking

- **The person** disconnects an app in the Geniffy app under **Agents and MCP**. It stops at once.
- **The app** revokes either token at `POST /oauth/revoke` (RFC 7009), which ends the connection.
- **Connecting again** replaces the app's previous connection rather than adding a second one.

## What a connection reaches

A connection reaches its owner's own memory and nothing else: not another person's, and not the spaces an
app built on the API keeps for its users. Only accounts that are open in Geniffy can connect. Every call is
recorded under **Requests** with the app's name, and your memory stays in India.

## Clients

| Method | Supported |
| --- | --- |
| Public clients (`token_endpoint_auth_method: none`) | Yes, with PKCE |
| `client_secret_basic`, `client_secret_post` | Yes |
| Grant types | `authorization_code`, `refresh_token` |

Source: https://docs.geniffy.com/mcp/sign-in
