Appearance
MCP Authentication
The Knowify MCP server uses OAuth 2.0 to authenticate connections. When you connect from Claude, the OAuth flow is handled automatically — you just log in with your Knowify credentials.
The MCP endpoint is hosted on assistant.knowify.com, while the OAuth provider remains on developers.knowify.com.
How It Works
Step by Step
Claude connects to the MCP endpoint and receives a
401 Unauthorizedresponse with aWWW-Authenticate: Bearerheader.OAuth discovery — Claude fetches
/.well-known/oauth-protected-resource/mcpto find the authorization server, then/.well-known/oauth-authorization-serverfor endpoint details.Dynamic client registration — Claude registers itself as an OAuth client via
POST /oauth/reg(RFC 7591). This happens automatically; no manual client setup is needed.Login — A browser window opens showing the Knowify login page. You enter your email and password, which are verified against the Knowify backend.
Token exchange — After login, Claude receives an authorization code and exchanges it for a JWT access token. The token includes your scopes and a resource indicator for the MCP server.
Authenticated session — Claude includes the JWT in all subsequent MCP requests. The server validates the token, resolves your Knowify session, and routes tool calls to the backend on your behalf.
Token Lifecycle
| Token | Lifetime | Purpose |
|---|---|---|
| Access token (JWT) | 15 minutes | Authenticates MCP requests |
| Refresh token | 14 days | Renews access tokens without re-login |
| Knowify session | 14 days | Proxies requests to the Knowify backend |
When your access token expires, Claude automatically refreshes it using the refresh token. You only need to re-login when the refresh token expires (after 14 days of inactivity).
Security
- PKCE (RFC 7636) — All MCP OAuth flows use Proof Key for Code Exchange with S256 challenge method.
- Resource Indicators (RFC 8707) — Access tokens are scoped to the MCP server resource (
/mcp). - JWT verification — Every MCP request is verified against the OAuth server's JWKS endpoint.
- Scope enforcement — Tools check your granted scopes before executing. Read operations require
{resource}:read, write operations require{resource}:write. - Rate limiting — 120 requests per minute per client.
Connecting from Claude Code
Add the server to your project's .mcp.json:
json
{
"mcpServers": {
"knowify": {
"type": "url",
"url": "https://assistant.knowify.com/api/v2/mcp"
}
}
}Or connect interactively:
bash
claude /mcp
# Select "Add Server" → URL → https://assistant.knowify.com/api/v2/mcpOn first connection, a browser window will open for you to log in. After authentication, Knowify resources will be available in your Claude session.
Connecting from Claude.ai
- Go to Settings > Integrations (or look for the MCP / Connectors section)
- Click Add Custom Connector
- Enter the server URL:
https://assistant.knowify.com/api/v2/mcp - Follow the login prompt to authenticate with your Knowify credentials
Troubleshooting
"Authentication Error: access_denied"
This usually means a stale browser session from a previous failed login attempt. Clear your cookies for the OAuth server domain and try again.
"Authentication required" on tool calls
Your access token has expired and could not be refreshed. Disconnect and reconnect the MCP server to re-authenticate.
"Insufficient scope" on tool calls
Your token doesn't include the required scope for this operation. This can happen if the OAuth client was registered with restricted scopes. Reconnect to get a fresh token with the correct scopes.