The Genezio MCP server uses OAuth 2.1 to authenticate an MCP client. The client acts as your Genezio user, with the permissions that you give it on the consent page: Read, Write, or both. When a client connects, Genezio opens the page Connect client to Genezio in your browser. The page shows the name of the client and two permissions: You can clear a permission that the client asks for, but one permission must stay selected. Click Allow access to connect, or Deny to refuse.

What each scope permits

  • A tool that only reads needs mcp:read.
  • A tool that changes data needs mcp:write.
  • A client does not see the tools that its scopes do not permit. If it calls one, Genezio tells it to connect again with the required permission.
  • The scopes do not give access to more brands. The client sees only the brands that your Genezio user can open.
The MCP tools reference gives the scope of each tool.

Token lifetime

The client refreshes the access token by itself. After 30 days with no use, you sign in again.

OAuth endpoints

The client finds these endpoints by itself. You need them only to write your own client. Each path is on the host of the MCP server. The server supports the authorization_code and refresh_token grants, with PKCE (S256). A public client has no client secret.

API keys and the MCP server

An API key of Genezio (gnz-...) works only with the REST API. The MCP server does not accept it. Use OAuth to connect an MCP client.