ApplyAll's MCP server uses OAuth 2.1 public clients. Assistants such as Claude, ChatGPT, and
Cursor register themselves at POST /oauth/register because they cannot hold a
pre-shared secret. Unauthenticated registration is required for MCP public clients, PKCE is mandatory, and the consent page shows the redirect host.
Registration is unauthenticated on purpose. Requiring an initial access token would reject the
assistants this server is built for. The authorization server metadata advertises that endpoint,
the authorization-code and refresh-token grants, and S256 PKCE.
Redirect URIs on the documentation hosts example, example.com, example.net, and example.org are rejected. Those names show up in automated
vulnerability reports and are not used by real clients.
A code is issued only after a signed-in user chooses Allow. The consent page names the client, marks an unverified dynamically registered client as unverified, and states the host the browser will return to. PKCE is required on every authorization request. The grant is scoped MCP access for that user, not a password or a website session.
Report a security issue to [email protected].