# How authentication works on the LeadTap.me MCP server

> The LeadTap.me MCP server accepts OAuth 2.1 (public clients, PKCE S256, dynamic client registration) or an API token. Scopes read and write, token lifetimes, metadata URLs and revocation.

Source: https://docs.leadtap.me/mcp/authentication/ · Last updated: 2026-10-09

The LeadTap.me MCP server accepts two credentials: OAuth 2.1 for apps such as claude.ai, and API tokens (`ltp_…`) for scripts and headless clients. Either one resolves to a single LeadTap.me account, and every tool acts on that account only.

## The two LeadTap.me credentials

| Credential | For | How you get it | Scopes |
|---|---|---|---|
| OAuth 2.1 | Apps: claude.ai, Claude Desktop, Cowork, Claude Code with the browser flow | You sign in on `app.leadtap.me`, see which app is asking and which scopes, and allow or deny | `read`, or `read` and `write`, as you allow |
| API token (`ltp_…`) | Scripts and headless clients | **Account & Billing → Claude & API** in the portal. The full token is shown once | Always both |

## Scopes: read and write

The `read` scope covers the 17 read-only tools; the `write` scope covers the 17 write tools that create or change something. A read-only authorization gets `INSUFFICIENT_SCOPE` on write tools. See which tools are which in the [tool catalog](https://docs.leadtap.me/mcp/tools/).

## OAuth details for integrators

The LeadTap.me authorization server supports public clients only, with PKCE S256 required.

| Item | Value |
|---|---|
| Authorization server metadata | `https://app.leadtap.me/.well-known/oauth-authorization-server` |
| Protected resource metadata | `https://app.leadtap.me/.well-known/oauth-protected-resource` |
| Client registration | Dynamic client registration at `/api/oauth/register`, or a client ID metadata document (an `https` URL as `client_id`) |
| Clients | Public clients only; PKCE S256 required |
| Authorization code | 10 minutes, single use |
| Access token (`lta_…`) | 1 hour |
| Refresh token (`ltr_…`) | 30 days, rotating; reusing an old refresh token revokes the whole grant |
| Revocation | `/api/oauth/revoke` (RFC 7009) |
| Loopback redirects | Accepted, such as `http://localhost:<port>/…` |

## How clients discover the OAuth flow

A request to `https://app.leadtap.me/api/mcp` without a valid credential gets `401` with a `WWW-Authenticate` header pointing at the protected resource metadata. That is how MCP clients find the authorization server and start the flow. A revoked, expired or foreign token gets the same `401`, without saying which.

## Revoking a credential

Revoking cuts access immediately: OAuth grants in **Account & Billing → Connected apps**, API tokens in **Account & Billing → Claude & API**. OAuth clients can also revoke their own tokens at `/api/oauth/revoke`.

## Related pages

- [Security and data](https://docs.leadtap.me/mcp/security/)
- [How to connect Claude to LeadTap.me](https://docs.leadtap.me/mcp/connect/)
- [MCP errors](https://docs.leadtap.me/mcp/errors/)
