Authentication

How MCP clients and API callers authenticate with Savi Finance: OAuth 2.1 with PKCE, dynamic client registration and bearer tokens.

MCP: OAuth 2.1 flow

The MCP server at https://mcp.financesavi.com follows the MCP authorization specification. Compliant clients complete these steps automatically:

  1. Request /.well-known/oauth-protected-resource to find the authorization server.
  2. Request /.well-known/oauth-authorization-server for endpoint metadata.
  3. Register with POST /register (client_name, redirect_uris) to receive a client_id.
  4. Open /authorize in a browser with response_type=code, client_id, redirect_uri, state and a PKCE code_challenge with code_challenge_method=S256.
  5. The user enters their email, then the 6-digit code Savi sends to it.
  6. Savi redirects to the redirect_uri with a single-use authorization code, valid for about 60 seconds.
  7. Exchange the code at POST /token with client_id, redirect_uri and code_verifier. The response contains an access_token of type Bearer.
  8. Call https://mcp.financesavi.com/mcp with Authorization: Bearer <access_token>.

PKCE with S256 is required. A 401 response includes a WWW-Authenticate header with a resource_metadata parameter that points clients at the discovery document.

MCP scopes

The authorization server advertises these scopes in its metadata: mcp, read:profile, read:accounts, read:transactions, read:categories, read:tags and read:analytics. The mcp scope grants access to all tools.

JSON-RPC API

Methods marked required in the API reference need an Authorization: Bearer <token> header on requests to https://api-v2.financesavi.com/rpc. Methods marked public need no token. The MCP access token is the same kind of bearer token the Savi apps use.