OAuth 2.1 for connectors
Discovery, dynamic registration, PKCE authorization, and company-pinned tokens for web connectors such as claude.ai and ChatGPT.
Web connectors discover and authorize access on their own, with OAuth 2.1 and PKCE. To connect from claude.ai: Settings → Connectors → Add custom connector with the URL https://app.tario.io/api/mcp; the consent screen opens automatically.
Discovery:
GET /.well-known/oauth-protected-resource/api/mcp(RFC 9728) andGET /.well-known/oauth-authorization-server(RFC 8414). A401on/api/mcpcarries theWWW-Authenticateheader with the discovery URL.Dynamic registration (RFC 7591):
POST /oauth/registerwithclient_nameandredirect_urisreturns aclient_id(public client, no secret).Authorization:
GET /oauth/authorizein the browser. The user logs in, chooses the company the connector may access, and approves. PKCE S256 is required.Token:
POST /oauth/tokenwithauthorization_codeandcode_verifierreturns an access token (1 hour) and a rotating refresh token (30 days).
- The token is pinned to the chosen company: the
X-Tario-Companyheader cannot change it. - The only scope is
read: connectors query, they do not write. - Personal tokens keep working with clients that allow headers, such as Claude Code.