> ## Documentation Index
> Fetch the complete documentation index at: https://docs.momentra.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Auth (OAuth 2.1 / CIMD)

> How the MCP server authenticates clients — OAuth 2.1 + PKCE with Client ID Metadata Documents, or a static bearer token.

The server is both the OAuth **authorization server** and the **resource
server**. The access token it issues is the same opaque `mck_` bearer the `/mcp`
path already understands, so both hosted clients converge on one credit-account
model.

## Discovery

* `GET /.well-known/oauth-protected-resource` (RFC 9728)
* `GET /.well-known/oauth-authorization-server` (RFC 8414)

## CIMD (no client registration)

The metadata advertises:

* `client_id_metadata_document_supported: true`
* `none` in `token_endpoint_auth_methods_supported`
* `authorization_response_iss_parameter_supported: true` (RFC 9207)

Claude and ChatGPT both pick CIMD from these, so there is **no Dynamic Client
Registration** and no pre-shared secret. `registration_endpoint` is intentionally
absent.

## Flow

<Steps>
  <Step title="Authorize">
    `GET /authorize` — PKCE `S256` required; `client_id` is the client's HTTPS
    metadata-document URL, and `redirect_uri` is validated against it.
  </Step>

  <Step title="Exchange the code">
    A single-use code → `POST /token` →
    `{access_token: "mck_…", token_type: "Bearer"}`.
  </Step>
</Steps>

<Note>
  **Connecting mints a 0-credit account.** `search` works right away; `fetch` and
  `index_org` return the checkout link until the account is topped up. The 100
  free credits stay tied to a real Stripe checkout, so connecting can't farm
  them.
</Note>

## Static bearer

For non-interactive clients (curl, scripts), skip OAuth and send
`Authorization: Bearer <mck_…>` from a Stripe checkout. It resolves to the same
credit account as the OAuth flow.

```bash theme={null}
curl -sS https://mcp.momentra.org/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -H 'authorization: Bearer mck_…' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search","arguments":{"query":"museum"}}}'
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.