tario.

OAuth 2.1 for connectors

Discovery, dynamic registration, PKCE authorization, and company-pinned tokens for web connectors such as claude.ai and ChatGPT.

Web connectors discover and authorize access on their own, with OAuth 2.1 and PKCE. To connect from claude.ai: Settings → Connectors → Add custom connector with the URL https://app.tario.io/api/mcp; the consent screen opens automatically.

  1. Discovery: GET /.well-known/oauth-protected-resource/api/mcp (RFC 9728) and GET /.well-known/oauth-authorization-server (RFC 8414). A 401 on /api/mcp carries the WWW-Authenticate header with the discovery URL.

  2. Dynamic registration (RFC 7591): POST /oauth/register with client_name and redirect_uris returns a client_id (public client, no secret).

  3. Authorization: GET /oauth/authorize in the browser. The user logs in, chooses the company the connector may access, and approves. PKCE S256 is required.

  4. Token: POST /oauth/token with authorization_code and code_verifier returns an access token (1 hour) and a rotating refresh token (30 days).

  • The token is pinned to the chosen company: the X-Tario-Company header cannot change it.
  • The only scope is read: connectors query, they do not write.
  • Personal tokens keep working with clients that allow headers, such as Claude Code.