Connected Apps (OAuth)
Connect MCP clients — Claude, ChatGPT, Cursor, VS Code, Grok, Windsurf and more — to your is.team account using OAuth 2.1 + PKCE. No tokens to copy or rotate. Each app asks for your approval once, and you can disconnect any of them with one click from Account Settings. Available on every plan, including Free.
Connecting an App
Most MCP clients only ask you for a server URL. is.team handles registration, consent and token issuance automatically. Step-by-step guides for each client are in the MCP Server docs.
- 1
Add a custom MCP server in your client
In Claude, open Connectors; in ChatGPT, create a developer-mode app; in Cursor or VS Code, use the one-click install or add the server to your MCP config.
- 2
Enter the is.team MCP URL
Paste
https://is.team/mcpas the server URL. The client discovers the OAuth metadata at/.well-known/oauth-protected-resourceand registers itself dynamically (RFC 7591). - 3
Approve the consent screen
Your browser opens is.team. Sign in if prompted, check the app name and where you'll be sent back to, choose the workspaces the app may access and click Allow. The app receives its tokens automatically.
- 4
Check Account Settings
Open Account Settings → Connected apps — the app is listed with its workspaces, when it connected and when it was last active.
Info
OAuth-connected apps use the remote MCP server's 17 tools — cards, tasks, comments, time logs and canvas. The full toolset, real-time card chat and integrations need the local agent.
Verified and Unverified Apps
Any MCP client can register itself, so the consent screen tells you what is.team actually knows about the app:
Verified app
The app's sign-in callback belongs to a client we recognize, such as Claude, ChatGPT, Cursor, VS Code or Grok. Its name and logo come from is.team.
Unverified app
The name was chosen by the app itself and no logo is shown. Only click Allow if you started the connection yourself and trust the app.
Tip
The consent screen also shows where you'll be sent back to — a website address, or "an app on this computer" for desktop apps and command-line tools. If that doesn't match the app you're connecting, click Deny.
OAuth vs Personal API Tokens
is.team supports both connection methods on every plan. Use OAuth whenever your client supports it.
OAuth (Connected apps)
For MCP clients like Claude, ChatGPT, Cursor and VS Code. One-click consent, limited to the workspaces you pick, short-lived access tokens that refresh automatically, and easy to disconnect.
Personal API tokens
For CI pipelines, headless scripts, clients without OAuth support and the @isteam/mcp local agent. Long-lived — you copy the token once and choose which workspaces it can reach.
Permissions & Scopes
is.team grants a single scope. Clients may request others — such as mcp:read, openid, profile, email or offline_access — but those are ignored rather than rejected, so the connection still works.
| Scope | What it grants |
|---|---|
| mcp | Read and update boards, cards and tasks in the workspaces you selected, through the remote MCP server's tools. |
Tip
Workspace selection is enforced server-side, and access follows your membership: tools can't reach a workspace you didn't check on the consent screen, or one you have since left.
Disconnecting an App
Disconnecting revokes every access and refresh token the app holds, immediately. The app has to ask for your approval again before it can call the API.
- 1
Open Account Settings
Click your avatar in the top-right corner and choose Account (Account Settings).
- 2
Switch to Connected apps
Select the Connected apps tab. Each row shows the app, whether it is verified, where it sends you back to, its workspaces, and when it connected and was last active.
- 3
Disconnect
Click the disconnect (trash) button next to the app and confirm. All of its tokens are revoked at once.
For Client Developers
Building an MCP client and want users to authenticate with is.team? The server implements the MCP authorization spec — protected resource metadata, authorization server discovery, dynamic client registration, authorization code with PKCE, resource indicators, refresh-token rotation and revocation.
Discovery
An unauthenticated request to /mcp returns 401 with a WWW-Authenticate header that points at the protected resource metadata. Both discovery documents are public and CORS-enabled:
# Protected resource metadata (RFC 9728)curl https://is.team/.well-known/oauth-protected-resourcecurl https://is.team/.well-known/oauth-protected-resource/mcp# Authorization server metadata (RFC 8414)curl https://is.team/.well-known/oauth-authorization-serverDynamic Client Registration
Register your client at runtime (RFC 7591) — no pre-registration required. Public clients use none and rely on PKCE; confidential clients can ask for client_secret_post or client_secret_basic.
curl -X POST https://is.team/api/oauth/register \ -H "Content-Type: application/json" \ -d '{ "client_name": "My MCP Client", "redirect_uris": ["https://example.com/oauth/callback"], "token_endpoint_auth_method": "none" }'- Redirect URIs may use
https, anhttploopback address (localhost,127.0.0.1,[::1]— any port matches) or your app's own scheme such ascursor:. - Up to 10 redirect URIs, without fragments or credentials. Schemes such as
javascript:,data:andfile:are rejected. - Unverified apps are shown with their registered name and no logo.
Authorization Code + PKCE
Send the user to the authorize endpoint with an S256 PKCE challenge and the MCP server as the resource (RFC 8707):
https://is.team/oauth/authorize? response_type=code &client_id={client_id} &redirect_uri={redirect_uri} &scope=mcp &state={state} &code_challenge={code_challenge} &code_challenge_method=S256 &resource=https%3A%2F%2Fis.team%2FmcpThe user is sent back to {redirect_uri}?code=…&state=…&iss=https%3A%2F%2Fis.team. Check that state matches and that iss is https://is.team (RFC 9207). Errors such as access_denied come back the same way.
Token Exchange
Exchange the authorization code for an access and refresh token:
curl -X POST https://is.team/api/oauth/token \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=authorization_code" \ -d "code={authorization_code}" \ -d "redirect_uri={redirect_uri}" \ -d "client_id={client_id}" \ -d "code_verifier={code_verifier}" \ -d "resource=https://is.team/mcp"Refresh & Revocation
Refresh tokens rotate on every use. If a response gets lost, the same refresh token can be retried for 60 seconds; reusing it after that revokes the whole token family.
curl -X POST https://is.team/api/oauth/token \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=refresh_token" \ -d "refresh_token={refresh_token}" \ -d "client_id={client_id}"To revoke a token explicitly, call the RFC 7009 endpoint. It always answers 200, even for unknown tokens:
curl -X POST https://is.team/api/oauth/revoke \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "token={access_or_refresh_token}" \ -d "token_type_hint=refresh_token" \ -d "client_id={client_id}"Calling the MCP Endpoint
Send the access token as a Bearer credential to the Streamable HTTP endpoint:
curl -X POST https://is.team/mcp \ -H "Authorization: Bearer ist_at_..." \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"my-client","version":"1.0.0"}}}'An expired or revoked token gets a 401 that tells the client how to sign in again. A request without a token gets the same challenge without the error fields.
HTTP/1.1 401 UnauthorizedWWW-Authenticate: Bearer realm="is-team-mcp", error="invalid_token", error_description="The access token is invalid, expired or revoked", resource_metadata="https://is.team/.well-known/oauth-protected-resource", scope="mcp"Security Notes
- • Access tokens live 1 hour, refresh tokens 30 days.
- • Tokens are stored hashed (SHA-256). The raw token is shown to the client only once.
- • Only the S256 PKCE method is accepted — plain code verifiers are rejected.
- • Refresh tokens rotate on every use, and replaying an old one after the 60-second grace revokes the whole family.
- • Access follows workspace membership — leaving a workspace cuts the app off from it.
- • An app's tokens only work with the MCP endpoint (
/mcp). Scripts that call the REST API need an API token. - • Disconnecting an app from Account Settings revokes every active token for that client immediately.
