Sesame Labs · Authentication Profile

Sesame Labs Authentication

Authentication

Sesame Labs secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyArtificial IntelligenceAdvertisingVideoMarketingGenerative AIMCPAgents
Methods: oauth2 Schemes: 1 OAuth flows: authorizationCode API key in:

Security Schemes

OAuth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

sesame-labs-authentication.yml Raw ↑
generated: '2026-07-21'
method: searched
source: https://app.usenotch.ai/.well-known/oauth-authorization-server
docs: https://app.usenotch.ai/mcp/setup
summary:
  types: [oauth2]
  oauth2_flows: [authorizationCode]
  api_keys: false
  notes: >-
    Notch has no API-key surface. Access is exclusively via the hosted MCP
    server, authenticated with browser-based OAuth 2.0. It is a public client
    (token_endpoint_auth_methods = none) using PKCE (S256) and RFC 7591 dynamic
    client registration, so MCP clients self-register with no pre-issued
    credentials.
schemes:
- name: OAuth2
  type: oauth2
  source: https://app.usenotch.ai/.well-known/oauth-authorization-server
  issuer: https://app.usenotch.ai
  flows:
  - flow: authorizationCode
    authorizationUrl: https://app.usenotch.ai/api/v1/mcp-auth/authorize
    tokenUrl: https://app.usenotch.ai/api/v1/mcp-auth/token
    registrationUrl: https://app.usenotch.ai/api/v1/mcp-auth/register
    revocationUrl: https://app.usenotch.ai/api/v1/mcp-auth/revoke
    grant_types: [authorization_code, refresh_token]
    response_types: [code]
    pkce_methods: [S256]
    token_endpoint_auth_methods: [none]
    scopes: []
protected_resource:
  resource: https://app.usenotch.ai/mcp
  authorization_servers: [https://app.usenotch.ai]
  bearer_methods_supported: [header]
  scopes_supported: []