How chat clients connect to your beamlet with OAuth.
You give the client your beamlet's MCP URL, such as
https://beamlet.example/beamlet/mcp. The client sends you to your
beamlet, where you sign in and choose a policy. That is the whole
setup: there is no client to register and no secret to copy. The
home page has the steps for each client. Clients without OAuth use
a token from beamlet tokens.create instead.
The client receives an access token that lives for a day, and refreshes it when it runs out. Each refresh keeps the connection for another thirty days, so a client you use at least once a month never asks you to sign in again.
beamlet tokens lists these tokens by the client's host. To cut a
client off, or to change its policy, delete its token and connect
again.
Every OAuth URL is built from the address your beamlet is reached
at: BEAMLET_URL on the standalone server, or the endpoint's url
config when embedded. If that address is wrong, clients cannot
connect.
Summary
Functions
How long an access token lives, in seconds: a day.
The authorization server metadata document (RFC 8414): the two endpoints and what the flow supports. No scopes are advertised; the policy is chosen on the consent page instead.
The beamlet's origin, which is also its OAuth issuer.
The protected resource metadata document (RFC 9728): the resource and its authorization server, this origin.
How long a refresh token lives, in seconds: thirty days from the last refresh.
The MCP URL a token is for, byte for byte what a client sends as resource.
The protected resource metadata URL the 401 challenge names.
Functions
@spec access_ttl() :: pos_integer()
How long an access token lives, in seconds: a day.
@spec authorization_server_metadata() :: map()
The authorization server metadata document (RFC 8414): the two endpoints and what the flow supports. No scopes are advertised; the policy is chosen on the consent page instead.
@spec issuer() :: String.t()
The beamlet's origin, which is also its OAuth issuer.
@spec protected_resource_metadata() :: map()
The protected resource metadata document (RFC 9728): the resource and its authorization server, this origin.
@spec refresh_ttl() :: pos_integer()
How long a refresh token lives, in seconds: thirty days from the last refresh.
@spec resource() :: String.t()
The MCP URL a token is for, byte for byte what a client sends as resource.
@spec resource_metadata_url() :: String.t()
The protected resource metadata URL the 401 challenge names.