OAuth 2.1 sign-in for MCP clients and other applications
Connecting an MCP client now needs only the server's address: the client is told to sign in, registers itself, and sends the person to a consent page on g1t. No token is pasted. - identity: authorization codes with PKCE (S256), grants with rotating refresh tokens, listing and revoking grants - client registration stores nothing: a client id encodes its own name and redirect addresses, so the open endpoint cannot be used to fill a database - api: authorization server and protected resource metadata, registration and token endpoints; the MCP server answers unauthenticated requests with 401 and a pointer to the metadata - site: consent page at /oauth/authorize, which never redirects to an address the client did not register; connected applications in Settings - docs, llms.txt, README and plan updated
No changes