OAuth and discovery
This page is for MCP client authors. If you use Cursor, VS Code, or Claude Code, the Connect page is all you need.
OAuth details
- PKCE
S256is required, and thecode_verifiermust be 43 to 128 unreserved characters (RFC 7636).resourceis optional; when sent it must behttps://mcp.blazium.games/mcporhttps://mcp.blazium.games(orhttps://mcp.blazium.games/playerfor the player server) (RFC 8707). - Access tokens last one hour. The token response includes a refresh token, rotated on every use, so clients renew without asking you to sign in again. Rotation keeps the original 30-day expiry: after 30 days the user signs in again.
- Each refresh token works once. Presenting a spent one revokes every token from that sign-in, so a stolen refresh token stops working as soon as either party uses it.
- Authorization codes work once and expire after 10 minutes.
- The consent page is protected against cross-site requests: Allow and Deny only work from the page itself.
- Scopes:
mcp:read,mcp:write, and the narrowermcp:catalog.write,mcp:build.write,mcp:crash.read,mcp:analytics.read,mcp:keys.manage, andmcp:money(see Scopes).mcp:read mcp:writeis granted when the client asks for none, unless the user ticks Read-only access or picks a preset on the consent page. The player server usesplayer:read,player:write, andplayer:buy. - Authorization responses include
iss(RFC 9207). Errors and Deny are sent back to the client aserror=...(RFC 6749). - Dynamic Client Registration (RFC 7591) at
https://mcp.blazium.games/oauth/registeraccepts https redirects, loopbackhttp://127.0.0.1andhttp://localhoston any port, and app schemes such ascursor://andvscode://(RFC 8252). Public clients usenone; confidential clients may useclient_secret_postorclient_secret_basic. - Client ID Metadata Documents (an https
client_id) are supported; only the document'sredirect_urisare accepted. - Loopback redirect URIs also work without registering a client.
- Unauthenticated
/mcpcalls return401withWWW-Authenticatenaming the resource metadata and scopes; a rejected token addserror="invalid_token".
Discovery
Clients and agents can find the server without any configuration:
- MCP server card:
https://mcp.blazium.games/.well-known/mcp/server-card.json(alsohttps://mcp.blazium.games/.well-known/mcp.json, and redirected fromhttps://blazium.games/.well-known/mcp.json). - Protected resource metadata (RFC 9728):
https://mcp.blazium.games/.well-known/oauth-protected-resource/mcp. - Authorization server metadata (RFC 8414):
https://mcp.blazium.games/.well-known/oauth-authorization-server(also/.well-known/openid-configuration). The path-suffixed forms/.well-known/oauth-authorization-server/mcpand/playeralso work; as RFC 8414 requires, they report the suffixed URL asissuerand setauthorization_response_iss_parameter_supportedtofalse. - Player server:
https://mcp.blazium.games/.well-known/mcp/player-server-card.json,https://mcp.blazium.games/.well-known/oauth-protected-resource/player, andhttps://mcp.blazium.games/.well-known/oauth-authorization-server/player. - llms.txt lists the server for AI agents.
The server card is generated from the running server, so it always matches the reference.