Authentication
The LeadSponsor MCP server authenticates every request with OAuth 2.1. You sign in with your LeadSponsor account and authorize a workspace; your client (Claude, ChatGPT) handles the token automatically. There's nothing to copy or store.
How it works
The server is an OAuth resource server. When a client connects:
- It calls the MCP endpoint without a token and gets a
401with aWWW-Authenticatechallenge that advertises the authorization server. - It discovers the authorization server (
auth.leadsponsor.io) via RFC 9728 Protected Resource Metadata and registers itself automatically (Dynamic Client Registration) — no client ID or secret to enter. - It sends you through LeadSponsor login (Google or email / password) and a workspace choice, then receives a short-lived access token (Authorization Code + PKCE).
- Every MCP request carries that token; the server validates its signature, issuer, audience, and expiry before serving any data.
Workspace scope
Each token is bound to one workspace (the ws claim, with the audience pinned to the MCP server per RFC 8707). A token issued for workspace A cannot read workspace B's data.
At sign-in you choose which workspace to authorize: regular users see the workspaces they belong to, and Dataxx admins see every workspace. To switch workspace, reconnect the connector and pick another one.
Sessions
Access tokens are short-lived and refreshed automatically by the client; removing the connector ends access. No secrets live on your machine.
Your LeadSponsor account email must be verified before you can authorize a connector.