How authentication works on the LeadTap.me MCP server
The LeadTap.me MCP server accepts two credentials: OAuth 2.1 for apps such as claude.ai, and API tokens (ltp_…) for scripts and headless clients. Either one resolves to a single LeadTap.me account, and every tool acts on that account only.
The two LeadTap.me credentials
Section titled “The two LeadTap.me credentials”| Credential | For | How you get it | Scopes |
|---|---|---|---|
| OAuth 2.1 | Apps: claude.ai, Claude Desktop, Cowork, Claude Code with the browser flow | You sign in on app.leadtap.me, see which app is asking and which scopes, and allow or deny |
read, or read and write, as you allow |
API token (ltp_…) |
Scripts and headless clients | Account & Billing → Claude & API in the portal. The full token is shown once | Always both |
Scopes: read and write
Section titled “Scopes: read and write”The read scope covers the 17 read-only tools; the write scope covers the 17 write tools that create or change something. A read-only authorization gets INSUFFICIENT_SCOPE on write tools. See which tools are which in the tool catalog.
OAuth details for integrators
Section titled “OAuth details for integrators”The LeadTap.me authorization server supports public clients only, with PKCE S256 required.
| Item | Value |
|---|---|
| Authorization server metadata | https://app.leadtap.me/.well-known/oauth-authorization-server |
| Protected resource metadata | https://app.leadtap.me/.well-known/oauth-protected-resource |
| Client registration | Dynamic client registration at /api/oauth/register, or a client ID metadata document (an https URL as client_id) |
| Clients | Public clients only; PKCE S256 required |
| Authorization code | 10 minutes, single use |
Access token (lta_…) |
1 hour |
Refresh token (ltr_…) |
30 days, rotating; reusing an old refresh token revokes the whole grant |
| Revocation | /api/oauth/revoke (RFC 7009) |
| Loopback redirects | Accepted, such as http://localhost:<port>/… |
How clients discover the OAuth flow
Section titled “How clients discover the OAuth flow”A request to https://app.leadtap.me/api/mcp without a valid credential gets 401 with a WWW-Authenticate header pointing at the protected resource metadata. That is how MCP clients find the authorization server and start the flow. A revoked, expired or foreign token gets the same 401, without saying which.
Revoking a credential
Section titled “Revoking a credential”Revoking cuts access immediately: OAuth grants in Account & Billing → Connected apps, API tokens in Account & Billing → Claude & API. OAuth clients can also revoke their own tokens at /api/oauth/revoke.