# Architecture Studio OAuth and scoped permissions

> Machine-readable permissions and authorization discovery for the Architecture Studio MCP.

## Discover and authorize

The MCP resource identifier is https://mcp.architecturestudio.ai/. Its RFC 9728 metadata declares the authorization server and scopes. Follow the WWW-Authenticate resource_metadata URL on a 401 response, validate the resource identifier, and discover the authorization endpoints from the named issuer. Use the authorization code flow with PKCE S256 through your host. Never put bearer tokens in URLs.

- [Authoritative protected-resource metadata](https://mcp.architecturestudio.ai/.well-known/oauth-protected-resource)
- [Authorization server metadata](https://clerk.architecturestudio.ai/.well-known/oauth-authorization-server)
- [OpenAPI OAuth security scheme](https://architecturestudio.ai/openapi.json)

## Current scopes

openid: identify the signed-in user. profile: read basic profile information. email: read email identity. The current MCP requires these three identity scopes. They are not separate project-read, project-write, or administration permissions, and this documentation does not invent such permissions. Do not request private_metadata, public_metadata, or offline_access merely because the identity provider supports them.

Tokens must be issued for the Arch Studio MCP and validated by the service. The website session does not replace the MCP bearer token. Consent and host permissions still govern which tools an assistant can use; user review remains necessary when a workflow calls for it.

- [Connect your host](https://architecturestudio.ai/docs/install)

## Authorization errors

For invalid_scope or invalid_grant, match your host and error to the known-issues guide.

- [Known issues and recovery](https://architecturestudio.ai/docs/known-issues)
