How an MCP client signs in to G2X with OAuth, registers itself, and uses its tokens.
The G2X MCP server is an OAuth 2.1 protected resource. A client finds its way to sign-in from the server itself:
tools/list or a tool without a token. The server answers 401 with a WWW-Authenticate: Bearer header whose resource_metadata names the protected-resource metadata.https://mcp.g2x.com/.well-known/oauth-protected-resource/mcp, or …/mcp/research for the research endpoint. Its authorization_servers names the authorization server.S256.Authorization header on every request.Discover the authorization server this way each time instead of hardcoding its address.
Register with dynamic client registration (RFC 7591) at the registration_endpoint the authorization server's metadata lists. Redirect URIs must use https, or http on the loopback address. Register once and reuse the client ID: registration is rate limited.
Request the openid and offline_access scopes, and use the refresh token to stay signed in. Keep tokens in your client's credential storage, never in a URL, a prompt or a log.
Every call runs as the signed-in G2X account. It sees what that account sees in G2X, and it can change only what that account can change.