> ## Documentation Index
> Fetch the complete documentation index at: https://docs.genseo.co/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth connection

> Sign in to Genseo MCP with OAuth 2.1 and PKCE. List projects, pick one per chat, and call allowlisted tools.

Genseo supports OAuth 2.1 with PKCE for hosted MCP connections. OAuth is the recommended connection method for the [Genseo ChatGPT app](/developers/chatgpt) and other connector marketplaces because users approve access in the browser and never copy an API key into the client.

## Connection flow

1. Add `https://api.genseo.co/mcp` as the remote MCP server.
2. Sign in to Genseo in the browser consent window.
3. Review and approve the requested access.
4. The client calls `genseo_projects_list` and asks which project this chat should use.
5. Every subsequent project tool includes that exact `project_id`.

An OAuth grant can discover every project available through the connected Genseo account. It does not combine project data: membership and project access are checked again for every operation.

## OAuth metadata

Protected Resource Metadata is available at:

```text theme={null}
https://api.genseo.co/.well-known/oauth-protected-resource
```

The authorization server advertises authorization, token, PKCE and dynamic-client-registration endpoints through its OAuth metadata. Access tokens must target the resource `https://api.genseo.co/mcp`.

## Consent and revocation

The consent screen explains that the connector can list account projects and use Genseo tools only inside an explicitly selected project. Disconnect the connector in the AI client or open **Project → Brand → API / Developer → OAuth connector access** and choose **Disconnect**. Revocation invalidates that client's active sessions and refresh tokens; connecting again requires a new browser consent.

OAuth does not grant access to billing, team administration, credentials, project creation or project deletion. Live autonomous writes additionally require [Agent Autopilot](/developers/agent-autopilot) to be enabled for that project.

## API keys compared with OAuth

| Authentication | Project access | Recommended use |
| - | - | - |
| OAuth | All projects available to the signed-in account; explicit `project_id` per tool | ChatGPT and hosted connectors |
| `gs_live_` API key | Exactly one project | CLI, backend automation and local MCP clients |

The existing CLI browser Device Flow continues to create a project-bound API key and is separate from marketplace OAuth.

## Marketplace acceptance scenarios

Use placeholder accounts and IDs only. Before submission, verify these positive end-to-end scenarios:

1. A new OAuth client registers dynamically, completes PKCE S256 consent and refreshes an expired access token.
2. An agency user lists five accessible customer projects and selects one project for a chat.
3. The agent reads an Issue with evidence, fixes the page through a separate CMS connector, starts one Recheck and marks the verified occurrence done.
4. With Agent Autonomy enabled, the agent generates, schedules and publishes a post through an already connected provider.
5. Revoking and reconnecting the grant invalidates the old refresh token and produces a new working connection.

Also verify these negative scenarios:

1. An ordinary Genseo browser-session token and a token with the wrong MCP audience both receive an authentication challenge.
2. A removed workspace member cannot read the former customer's project, even with a previously valid project ID.
3. A burst above a request, write, Audit or Recheck limit receives `429` and does not start a crawl, AI request or publish action.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.