Skip to content

MCP Authentication ​

The Knowify MCP server uses OAuth 2.0 to authenticate connections. When you connect from Claude, the OAuth flow is handled automatically — you just log in with your Knowify credentials.

The MCP endpoint is hosted on assistant.knowify.com, while the OAuth provider remains on developers.knowify.com.

How It Works ​

Step by Step ​

  1. Claude connects to the MCP endpoint and receives a 401 Unauthorized response with a WWW-Authenticate: Bearer header.

  2. OAuth discovery — Claude fetches /.well-known/oauth-protected-resource/mcp to find the authorization server, then /.well-known/oauth-authorization-server for endpoint details.

  3. Dynamic client registration — Claude registers itself as an OAuth client via POST /oauth/reg (RFC 7591). This happens automatically; no manual client setup is needed.

  4. Login — A browser window opens showing the Knowify login page. You enter your email and password, which are verified against the Knowify backend.

  5. Token exchange — After login, Claude receives an authorization code and exchanges it for a JWT access token. The token includes your scopes and a resource indicator for the MCP server.

  6. Authenticated session — Claude includes the JWT in all subsequent MCP requests. The server validates the token, resolves your Knowify session, and routes tool calls to the backend on your behalf.

Token Lifecycle ​

TokenLifetimePurpose
Access token (JWT)15 minutesAuthenticates MCP requests
Refresh token14 daysRenews access tokens without re-login
Knowify session14 daysProxies requests to the Knowify backend

When your access token expires, Claude automatically refreshes it using the refresh token. You only need to re-login when the refresh token expires (after 14 days of inactivity).

Security ​

  • PKCE (RFC 7636) — All MCP OAuth flows use Proof Key for Code Exchange with S256 challenge method.
  • Resource Indicators (RFC 8707) — Access tokens are scoped to the MCP server resource (/mcp).
  • JWT verification — Every MCP request is verified against the OAuth server's JWKS endpoint.
  • Scope enforcement — Tools check your granted scopes before executing. Read operations require {resource}:read, write operations require {resource}:write.
  • Rate limiting — 120 requests per minute per client.

Connecting from Claude Code ​

Add the server to your project's .mcp.json:

json
{
  "mcpServers": {
    "knowify": {
      "type": "url",
      "url": "https://assistant.knowify.com/api/v2/mcp"
    }
  }
}

Or connect interactively:

bash
claude /mcp
# Select "Add Server" → URL → https://assistant.knowify.com/api/v2/mcp

On first connection, a browser window will open for you to log in. After authentication, Knowify resources will be available in your Claude session.

Connecting from Claude.ai ​

  1. Go to Settings > Integrations (or look for the MCP / Connectors section)
  2. Click Add Custom Connector
  3. Enter the server URL: https://assistant.knowify.com/api/v2/mcp
  4. Follow the login prompt to authenticate with your Knowify credentials

Troubleshooting ​

"Authentication Error: access_denied" ​

This usually means a stale browser session from a previous failed login attempt. Clear your cookies for the OAuth server domain and try again.

"Authentication required" on tool calls ​

Your access token has expired and could not be refreshed. Disconnect and reconnect the MCP server to re-authenticate.

"Insufficient scope" on tool calls ​

Your token doesn't include the required scope for this operation. This can happen if the OAuth client was registered with restricted scopes. Reconnect to get a fresh token with the correct scopes.