Connection flow
- Add
https://api.genseo.co/mcpas the remote MCP server. - Sign in to Genseo in the browser consent window.
- Review and approve the requested access.
- The client calls
genseo_projects_listand asks which project this chat should use. - Every subsequent project tool includes that exact
project_id.
OAuth metadata
Protected Resource Metadata is available at:https://api.genseo.co/mcp.
Consent and revocation
The consent screen explains that the connector can list account projects and use Genseo tools only inside an explicitly selected project. Disconnect the connector in the AI client or open Project → Brand → API / Developer → OAuth connector access and choose Disconnect. Revocation invalidates that client’s active sessions and refresh tokens; connecting again requires a new browser consent. OAuth does not grant access to billing, team administration, credentials, project creation or project deletion. Live autonomous writes additionally require Agent Autopilot to be enabled for that project.API keys compared with OAuth
The existing CLI browser Device Flow continues to create a project-bound API key and is separate from marketplace OAuth.
Marketplace acceptance scenarios
Use placeholder accounts and IDs only. Before submission, verify these positive end-to-end scenarios:- A new OAuth client registers dynamically, completes PKCE S256 consent and refreshes an expired access token.
- An agency user lists five accessible customer projects and selects one project for a chat.
- The agent reads an Issue with evidence, fixes the page through a separate CMS connector, starts one Recheck and marks the verified occurrence done.
- With Agent Autonomy enabled, the agent generates, schedules and publishes a post through an already connected provider.
- Revoking and reconnecting the grant invalidates the old refresh token and produces a new working connection.
- An ordinary Genseo browser-session token and a token with the wrong MCP audience both receive an authentication challenge.
- A removed workspace member cannot read the former customer’s project, even with a previously valid project ID.
- A burst above a request, write, Audit or Recheck limit receives
429and does not start a crawl, AI request or publish action.