Beamlet.OAuth (Beamlet v0.1.0)

Copy Markdown View Source

How chat clients connect to your beamlet with OAuth.

You give the client your beamlet's MCP URL, such as https://beamlet.example/beamlet/mcp. The client sends you to your beamlet, where you sign in and choose a policy. That is the whole setup: there is no client to register and no secret to copy. The home page has the steps for each client. Clients without OAuth use a token from beamlet tokens.create instead.

The client receives an access token that lives for a day, and refreshes it when it runs out. Each refresh keeps the connection for another thirty days, so a client you use at least once a month never asks you to sign in again.

beamlet tokens lists these tokens by the client's host. To cut a client off, or to change its policy, delete its token and connect again.

Every OAuth URL is built from the address your beamlet is reached at: BEAMLET_URL on the standalone server, or the endpoint's url config when embedded. If that address is wrong, clients cannot connect.

Summary

Functions

How long an access token lives, in seconds: a day.

The authorization server metadata document (RFC 8414): the two endpoints and what the flow supports. No scopes are advertised; the policy is chosen on the consent page instead.

The beamlet's origin, which is also its OAuth issuer.

The protected resource metadata document (RFC 9728): the resource and its authorization server, this origin.

How long a refresh token lives, in seconds: thirty days from the last refresh.

The MCP URL a token is for, byte for byte what a client sends as resource.

The protected resource metadata URL the 401 challenge names.

Functions

access_ttl()

@spec access_ttl() :: pos_integer()

How long an access token lives, in seconds: a day.

authorization_server_metadata()

@spec authorization_server_metadata() :: map()

The authorization server metadata document (RFC 8414): the two endpoints and what the flow supports. No scopes are advertised; the policy is chosen on the consent page instead.

issuer()

@spec issuer() :: String.t()

The beamlet's origin, which is also its OAuth issuer.

protected_resource_metadata()

@spec protected_resource_metadata() :: map()

The protected resource metadata document (RFC 9728): the resource and its authorization server, this origin.

refresh_ttl()

@spec refresh_ttl() :: pos_integer()

How long a refresh token lives, in seconds: thirty days from the last refresh.

resource()

@spec resource() :: String.t()

The MCP URL a token is for, byte for byte what a client sends as resource.

resource_metadata_url()

@spec resource_metadata_url() :: String.t()

The protected resource metadata URL the 401 challenge names.