Skip to content

How authentication works on the LeadTap.me MCP server

The LeadTap.me MCP server accepts two credentials: OAuth 2.1 for apps such as claude.ai, and API tokens (ltp_…) for scripts and headless clients. Either one resolves to a single LeadTap.me account, and every tool acts on that account only.

Credential For How you get it Scopes
OAuth 2.1 Apps: claude.ai, Claude Desktop, Cowork, Claude Code with the browser flow You sign in on app.leadtap.me, see which app is asking and which scopes, and allow or deny read, or read and write, as you allow
API token (ltp_…) Scripts and headless clients Account & Billing → Claude & API in the portal. The full token is shown once Always both

The read scope covers the 17 read-only tools; the write scope covers the 17 write tools that create or change something. A read-only authorization gets INSUFFICIENT_SCOPE on write tools. See which tools are which in the tool catalog.

The LeadTap.me authorization server supports public clients only, with PKCE S256 required.

Item Value
Authorization server metadata https://app.leadtap.me/.well-known/oauth-authorization-server
Protected resource metadata https://app.leadtap.me/.well-known/oauth-protected-resource
Client registration Dynamic client registration at /api/oauth/register, or a client ID metadata document (an https URL as client_id)
Clients Public clients only; PKCE S256 required
Authorization code 10 minutes, single use
Access token (lta_…) 1 hour
Refresh token (ltr_…) 30 days, rotating; reusing an old refresh token revokes the whole grant
Revocation /api/oauth/revoke (RFC 7009)
Loopback redirects Accepted, such as http://localhost:<port>/…

A request to https://app.leadtap.me/api/mcp without a valid credential gets 401 with a WWW-Authenticate header pointing at the protected resource metadata. That is how MCP clients find the authorization server and start the flow. A revoked, expired or foreign token gets the same 401, without saying which.

Revoking cuts access immediately: OAuth grants in Account & Billing → Connected apps, API tokens in Account & Billing → Claude & API. OAuth clients can also revoke their own tokens at /api/oauth/revoke.