Skip to main content

Authorization

  • OAuth 2.1 authorization code flow with PKCE. code_challenge_method=S256 is required, and so is state.
  • Public clients only: token_endpoint_auth_method is none. Send client_id in the form body; a Basic Authorization header or a client_secret is refused with invalid_request.
  • resource=https://mcp.nanocorp.so (RFC 8707). A trailing slash is accepted. When it is absent or empty, the request is bound to the MCP server.
  • scope=nanocorp, which grants the user’s full access. openid and offline_access are accepted and ignored.
  • No nonce is needed and no ID token is issued.
  • Every redirect back to the client carries iss (RFC 9207).
  • prompt=none returns a code when the user’s consent is current. Otherwise a pre-registered client gets login_required or consent_required. Any other prompt value, and max_age, is refused with invalid_request. response_mode must be query when sent.
  • Until a user has approved your redirect URI, an authorization error for a self-registered client (prompt=none included) is shown to the user on a NanoCorp page instead of being redirected to you.
  • Redirect URIs are compared exactly, except the port of a native client’s http loopback redirect.
Consent is remembered per user and client, for the redirect URI the user last approved. It is asked again for another redirect URI, a changed list of redirect URIs, a new registration, or when NanoCorp updates its consent page.

Client registration

Use one of three ways:
  1. Client ID metadata document. Your client_id is the https URL of a JSON document you publish, with a path and no query or fragment. The document’s client_id must equal that URL exactly, and it needs client_name and redirect_uris. When it lists token_endpoint_auth_methods_supported, the list must include none; without that list, token_endpoint_auth_method must be none or absent. Serve it from a public address, as application/json, without redirects, within 10 seconds and 64 KB. It is cached for up to 24 hours (max-age is honored). The confirmation page shows its host as the source of the app details.
  2. Dynamic client registration (RFC 7591) at POST https://accounts.nanocorp.so/oidc/register:
    • redirect_uris: 1 to 10 entries. web clients (the default application_type) use https only; native clients may also use http on 127.0.0.1, [::1] or localhost, with any port and path.
    • grant_types: absent, or a list that includes authorization_code. Other grants you list are ignored: the registration is stored as authorization_code only.
    • response_types: absent or ["code"]. token_endpoint_auth_method: absent or none.
    • client_name: required, 1 to 64 characters. client_uri: optional, https. logo_uri and unknown fields are ignored.
    The response is 201 with your client_id, client_id_issued_at and the accepted metadata. No secret is issued.
  3. Pre-registered client. Write to support@nanocorp.so if you need a fixed client ID. The confirmation page then shows your name as Registered with NanoCorp. Meta Muse uses the pre-registered client ID nca_ed8095a90ede567a36e12ca1.

Tokens and revocation

Exchange the code at POST https://accounts.nanocorp.so/oidc/token with grant_type=authorization_code, code, redirect_uri, client_id and code_verifier. The response is:
The access token is opaque and does not expire. There is no refresh token. It works on the MCP endpoint only. A user keeps at most 100 live tokens per client: the 101st revokes the oldest. Revoke a token when the user disconnects: POST https://accounts.nanocorp.so/oidc/revoke, form-encoded, with token and client_id (RFC 7009). A well-formed request always gets 200, whether or not the token was live. A revoked token stops working within a minute.