Skip to documentation
Browse documentation

Connect with OAuth

Connect consumer MCP clients through OAuth 2.1.

View raw

Upscrape implements an OAuth 2.1 authorization server for consumer MCP clients. The user signs in to Upscrape and authorizes the client without copying an API key into it.

Endpoint roles

MCP resource:        https://data.upscrape.com/mcp
Authorization host: https://app.upscrape.com

The resource server publishes protected-resource metadata. The authorization server publishes its own metadata and handles authorization, token exchange, refresh, revocation, and client registration.

Connect

In a client that supports remote MCP OAuth, add this server URL:

https://data.upscrape.com/mcp

The client should discover the authorization server, register or identify itself, start an authorization-code flow with PKCE S256, and redirect the browser to Upscrape. After approval, it exchanges the code for an opaque audience-bound access token.

Do not append /mcp to https://app.upscrape.com; that origin is the authorization server, not the MCP resource endpoint.

Supported OAuth behavior

  • Authorization Code with PKCE S256
  • public clients
  • dynamic client registration and client-ID metadata documents
  • opaque access tokens bound to the MCP resource audience
  • rotating refresh tokens with replay containment
  • token revocation
  • mcp or mcp:read, optionally constrained by platform/capability scopes

The current mcp scope gives the connector the account access needed to discover and execute published capabilities at their published credit costs. It is not a read-only scope and it is not limited to one platform.

It also allows reading job results across your account, including jobs started by other applications. Full results remain available through MCP chunk retrieval.

Keep the newest refresh token and serialize refresh requests. Reusing an older rotated token while its replacement chain is active revokes that user's access and refresh credentials for the same client and MCP resource. Reconnect through browser consent after this happens. Other clients are unaffected.

Every app you connect is listed under Connected apps on the Access page of the console, with when it was last active. Disconnect it there when it no longer needs access: its access and refresh tokens stop working at once, and it can connect again only through a new consent. Use scoped access to narrow a new grant. The consent page can restrict platform access and disable execution. Existing mcp grants keep their full-account semantics until replaced or revoked.

Host-scoped browser sessions

Browser sessions are host-scoped. The authorization flow deliberately redirects through the app. host where the user's Upscrape session exists. A client should follow discovered metadata and redirect URLs rather than synthesizing them.

Credit prices and plans: Upscrape pricing