Authentication
How MCP clients and API callers authenticate with Savi Finance: OAuth 2.1 with PKCE, dynamic client registration and bearer tokens.
MCP: OAuth 2.1 flow
The MCP server at https://mcp.financesavi.com follows the MCP authorization specification. Compliant clients complete these steps automatically:
- Request
/.well-known/oauth-protected-resourceto find the authorization server. - Request
/.well-known/oauth-authorization-serverfor endpoint metadata. - Register with
POST /register(client_name,redirect_uris) to receive aclient_id. - Open
/authorizein a browser withresponse_type=code,client_id,redirect_uri,stateand a PKCEcode_challengewithcode_challenge_method=S256. - The user enters their email, then the 6-digit code Savi sends to it.
- Savi redirects to the
redirect_uriwith a single-use authorizationcode, valid for about 60 seconds. - Exchange the code at
POST /tokenwithclient_id,redirect_uriandcode_verifier. The response contains anaccess_tokenof typeBearer. - Call
https://mcp.financesavi.com/mcpwithAuthorization: Bearer <access_token>.
PKCE with S256 is required. A 401 response includes a WWW-Authenticate header with a resource_metadata parameter that points clients at the discovery document.
MCP scopes
The authorization server advertises these scopes in its metadata: mcp, read:profile, read:accounts, read:transactions, read:categories, read:tags and read:analytics. The mcp scope grants access to all tools.
JSON-RPC API
Methods marked required in the API reference need an Authorization: Bearer <token> header on requests to https://api-v2.financesavi.com/rpc. Methods marked public need no token. The MCP access token is the same kind of bearer token the Savi apps use.