Skip to main content
Genseo supports OAuth 2.1 with PKCE for hosted MCP connections. OAuth is the recommended connection method for the Genseo ChatGPT app and other connector marketplaces because users approve access in the browser and never copy an API key into the client.

Connection flow

  1. Add https://api.genseo.co/mcp as the remote MCP server.
  2. Sign in to Genseo in the browser consent window.
  3. Review and approve the requested access.
  4. The client calls genseo_projects_list and asks which project this chat should use.
  5. Every subsequent project tool includes that exact project_id.
An OAuth grant can discover every project available through the connected Genseo account. It does not combine project data: membership and project access are checked again for every operation.

OAuth metadata

Protected Resource Metadata is available at:
The authorization server advertises authorization, token, PKCE and dynamic-client-registration endpoints through its OAuth metadata. Access tokens must target the resource https://api.genseo.co/mcp. The consent screen explains that the connector can list account projects and use Genseo tools only inside an explicitly selected project. Disconnect the connector in the AI client or open Project → Brand → API / Developer → OAuth connector access and choose Disconnect. Revocation invalidates that client’s active sessions and refresh tokens; connecting again requires a new browser consent. OAuth does not grant access to billing, team administration, credentials, project creation or project deletion. Live autonomous writes additionally require Agent Autopilot to be enabled for that project.

API keys compared with OAuth

The existing CLI browser Device Flow continues to create a project-bound API key and is separate from marketplace OAuth.

Marketplace acceptance scenarios

Use placeholder accounts and IDs only. Before submission, verify these positive end-to-end scenarios:
  1. A new OAuth client registers dynamically, completes PKCE S256 consent and refreshes an expired access token.
  2. An agency user lists five accessible customer projects and selects one project for a chat.
  3. The agent reads an Issue with evidence, fixes the page through a separate CMS connector, starts one Recheck and marks the verified occurrence done.
  4. With Agent Autonomy enabled, the agent generates, schedules and publishes a post through an already connected provider.
  5. Revoking and reconnecting the grant invalidates the old refresh token and produces a new working connection.
Also verify these negative scenarios:
  1. An ordinary Genseo browser-session token and a token with the wrong MCP audience both receive an authentication challenge.
  2. A removed workspace member cannot read the former customer’s project, even with a previously valid project ID.
  3. A burst above a request, write, Audit or Recheck limit receives 429 and does not start a crawl, AI request or publish action.