# `Beamlet.OAuth`
[🔗](https://github.com/aaronrussell/beamlet/blob/v0.1.0/lib/beamlet/oauth.ex#L1)

How chat clients connect to your beamlet with OAuth.

You give the client your beamlet's MCP URL, such as
`https://beamlet.example/beamlet/mcp`. The client sends you to your
beamlet, where you sign in and choose a policy. That is the whole
setup: there is no client to register and no secret to copy. The
home page has the steps for each client. Clients without OAuth use
a token from `beamlet tokens.create` instead.

The client receives an access token that lives for a day, and
refreshes it when it runs out. Each refresh keeps the connection
for another thirty days, so a client you use at least once a month
never asks you to sign in again.

`beamlet tokens` lists these tokens by the client's host. To cut a
client off, or to change its policy, delete its token and connect
again.

Every OAuth URL is built from the address your beamlet is reached
at: `BEAMLET_URL` on the standalone server, or the endpoint's `url`
config when embedded. If that address is wrong, clients cannot
connect.

# `access_ttl`

```elixir
@spec access_ttl() :: pos_integer()
```

How long an access token lives, in seconds: a day.

# `authorization_server_metadata`

```elixir
@spec authorization_server_metadata() :: map()
```

The authorization server metadata document (RFC 8414): the two
endpoints and what the flow supports. No scopes are advertised; the
policy is chosen on the consent page instead.

# `issuer`

```elixir
@spec issuer() :: String.t()
```

The beamlet's origin, which is also its OAuth issuer.

# `protected_resource_metadata`

```elixir
@spec protected_resource_metadata() :: map()
```

The protected resource metadata document (RFC 9728): the resource and its authorization server, this origin.

# `refresh_ttl`

```elixir
@spec refresh_ttl() :: pos_integer()
```

How long a refresh token lives, in seconds: thirty days from the last refresh.

# `resource`

```elixir
@spec resource() :: String.t()
```

The MCP URL a token is for, byte for byte what a client sends as `resource`.

# `resource_metadata_url`

```elixir
@spec resource_metadata_url() :: String.t()
```

The protected resource metadata URL the 401 challenge names.

---

*Consult [api-reference.md](api-reference.md) for complete listing*
