MCP server

Authentication

Sign in once with OAuth, or create a connector token for a client that reads a config file.

Every request to the MCP server carries a bearer credential that stands for one person: you. There are two ways to get one, and they end in the same place. Both appear in the same list under Connections, both reach exactly what you can reach, and both are removed the same way.

Sign in (OAuth)Connector token
Best forClaude, Claude Code, Cursor, VS CodeConfig files, scripts, clients without OAuth
What you doPress Connect in the browserCreate a token and paste it
Shown in Connections asApproved connectionThe token's name and its first characters
ExpiresNo, lasts until revokedNot unless you set one

Sign in with OAuth

This is what happens when you add the server by URL alone.

  1. Your client registers itself

    It asks the server where to authenticate and registers as an app. No secret is issued; the exchange is protected with PKCE instead.

  2. Oleon opens in your browser

    The approval page lives on oleon.io, where you normally sign in, so passkeys, two-factor authentication and your existing session all work. If you are already signed in, there is no password to type.

  3. You approve

    The page shows the app asking for access and the account it will act as. Press Connect to approve, or Cancel to refuse.

  4. Your client receives a credential

    The browser returns you to the client, which exchanges a one-time code for a credential and stores it. You never see or copy it.

Check the email on the approval page before pressing Connect. If you use more than one Oleon account, sign out and back in as the right one first.

Create a connector token

  1. Open Connections

    In Oleon Workspace, open your profile and choose the Connections tab.

  2. Create the token

    Press New token and name it after the client you are connecting, such as Claude on my laptop, so you know which one to revoke later. Press Create.

  3. Copy it now

    The token is shown once, with a ready-made client configuration beside it. Copy it before pressing I have copied it: Oleon stores only a hash and cannot show it again.

  4. Add it to your client

    Send it as a header on every request:

    HTTP
    Authorization: Bearer mcp_sk_your_token

    Connect a client has the exact configuration for each client.

Connector tokens start with mcp_sk_. You can hold up to 10 at once; revoke one to make room for another.

Giving a token an expiry

A token created in Oleon Workspace lasts until you revoke it. A token created through the API can be given an end date instead, by sending expires_at as an ISO date and time:

JSON
{ "name": "CI reader", "expires_at": "2027-01-31T00:00:00Z" }

It stops working at that moment with no further action, and until then it behaves like any other token. This is worth using for anything unattended, such as a script or a build agent, where nobody is watching for a token that outlived its job.

A connector token is as powerful as your own sign-in for everything the MCP server can do. Keep it out of shared files and repositories, and revoke it the moment you think it has been exposed.

Revoke a connection

Open Connections in your profile, press the delete button beside the connection and confirm with Revoke. Any client using it stops working within seconds, and your other connections are unaffected.

Each entry shows when it was last used, which makes old connections easy to find and remove.

What a credential cannot do

A credential used by an MCP client can read your workspace through the tools. It cannot manage connections. Creating tokens, revoking them and approving new connections all require you to be signed in to Oleon Workspace in person.

So if a token leaks, whoever holds it cannot create a replacement for themselves or remove your other connections before you notice. Revoking it ends their access.

No refresh tokens

Nothing here refreshes. A credential from the OAuth flow does not expire on a timer at all, and a connector token expires only if you gave it an end date when you created it. Otherwise a connection lasts until you revoke it, or until the account it belongs to loses access.