Your MCP client needs Streamable HTTP transport and OAuth support. Use server metadata to discover the authorization configuration.
- Authorization discovery
- An HTTP 401 response points to Protected Resource Metadata in the WWW-Authenticate header. The client discovers the authorization server there and starts Authorization Code with PKCE S256 and the resource https://api.obligacje.io/mcp.
- Application identity
- Publish a JSON document at a public HTTPS URL with a non-root path. client_id must exactly equal that URL. Include client_name, redirect_uris, token_endpoint_auth_method: none, grant_types: [authorization_code] and response_types: [code]. Add refresh_token to grant_types if your client refreshes access. Send the document URL as client_id in authorization requests. Dynamic registration (DCR) is unavailable.
- Callbacks and permissions
- Register exact HTTPS callback URLs. Native clients can use HTTP on localhost, 127.0.0.1 or [::1]; only the port may vary during registration matching. Code exchange must repeat the exact URI from authorization. Wildcards, LAN addresses and custom URI schemes are unsupported. Request only the permissions you need: catalog:read and optionally assistant:turn.
- Feature discovery
- After authorization, call initialize and tools/list. Tool descriptions and schemas provide the integration’s current capabilities. A regular API token or browser session does not replace an MCP OAuth token.