MCP server
Authentication
Sign in once with OAuth, or create a connector token for a client that reads a config file.
Every request to the MCP server carries a bearer credential that stands for one person: you. There are two ways to get one, and they end in the same place. Both appear in the same list under Connections, both reach exactly what you can reach, and both are removed the same way.
| Sign in (OAuth) | Connector token | |
|---|---|---|
| Best for | Claude, Claude Code, Cursor, VS Code | Config files, scripts, clients without OAuth |
| What you do | Press Connect in the browser | Create a token and paste it |
| Shown in Connections as | Approved connection | The token's name and its first characters |
| Expires | No, lasts until revoked | Not unless you set one |
Sign in with OAuth
This is what happens when you add the server by URL alone.
Your client registers itself
It asks the server where to authenticate and registers as an app. No secret is issued; the exchange is protected with PKCE instead.
Oleon opens in your browser
The approval page lives on
oleon.io, where you normally sign in, so passkeys, two-factor authentication and your existing session all work. If you are already signed in, there is no password to type.You approve
The page shows the app asking for access and the account it will act as. Press Connect to approve, or Cancel to refuse.
Your client receives a credential
The browser returns you to the client, which exchanges a one-time code for a credential and stores it. You never see or copy it.
Check the email on the approval page before pressing Connect. If you use more than one Oleon account, sign out and back in as the right one first.
Create a connector token
Open Connections
In Oleon Workspace, open your profile and choose the Connections tab.
Create the token
Press New token and name it after the client you are connecting, such as
Claude on my laptop, so you know which one to revoke later. Press Create.Copy it now
The token is shown once, with a ready-made client configuration beside it. Copy it before pressing I have copied it: Oleon stores only a hash and cannot show it again.
Add it to your client
Send it as a header on every request:
HTTP Authorization: Bearer mcp_sk_your_tokenConnect a client has the exact configuration for each client.
Connector tokens start with mcp_sk_. You can hold up to 10 at once; revoke one to make room for another.
Giving a token an expiry
A token created in Oleon Workspace lasts until you revoke it. A token created through the API can be given an end date instead, by sending expires_at as an ISO date and time:
{ "name": "CI reader", "expires_at": "2027-01-31T00:00:00Z" }It stops working at that moment with no further action, and until then it behaves like any other token. This is worth using for anything unattended, such as a script or a build agent, where nobody is watching for a token that outlived its job.
A connector token is as powerful as your own sign-in for everything the MCP server can do. Keep it out of shared files and repositories, and revoke it the moment you think it has been exposed.
Revoke a connection
Open Connections in your profile, press the delete button beside the connection and confirm with Revoke. Any client using it stops working within seconds, and your other connections are unaffected.
Each entry shows when it was last used, which makes old connections easy to find and remove.
What a credential cannot do
A credential used by an MCP client can read your workspace through the tools. It cannot manage connections. Creating tokens, revoking them and approving new connections all require you to be signed in to Oleon Workspace in person.
So if a token leaks, whoever holds it cannot create a replacement for themselves or remove your other connections before you notice. Revoking it ends their access.
No refresh tokens
Nothing here refreshes. A credential from the OAuth flow does not expire on a timer at all, and a connector token expires only if you gave it an end date when you created it. Otherwise a connection lasts until you revoke it, or until the account it belongs to loses access.
