Skip to main content

Authentication

The LeadSponsor MCP server authenticates every request with OAuth 2.1. You sign in with your LeadSponsor account and authorize a workspace; your client (Claude, ChatGPT) handles the token automatically. There's nothing to copy or store.

How it works​

The server is an OAuth resource server. When a client connects:

  1. It calls the MCP endpoint without a token and gets a 401 with a WWW-Authenticate challenge that advertises the authorization server.
  2. It discovers the authorization server (auth.leadsponsor.io) via RFC 9728 Protected Resource Metadata and registers itself automatically (Dynamic Client Registration) — no client ID or secret to enter.
  3. It sends you through LeadSponsor login (Google or email / password) and a workspace choice, then receives a short-lived access token (Authorization Code + PKCE).
  4. Every MCP request carries that token; the server validates its signature, issuer, audience, and expiry before serving any data.

Workspace scope​

Each token is bound to one workspace (the ws claim, with the audience pinned to the MCP server per RFC 8707). A token issued for workspace A cannot read workspace B's data.

At sign-in you choose which workspace to authorize: regular users see the workspaces they belong to, and Dataxx admins see every workspace. To switch workspace, reconnect the connector and pick another one.

Sessions​

Access tokens are short-lived and refreshed automatically by the client; removing the connector ends access. No secrets live on your machine.

Email verification

Your LeadSponsor account email must be verified before you can authorize a connector.