# Silicon Valley Atlas auth.md

How an agent authenticates to Silicon Valley Atlas. The MCP server at https://svatlas.io/mcp accepts OAuth 2.1 bearer tokens. Every token acts as one person who approved it; there are no API keys and no service accounts.

1. **Discover.** An unauthenticated call to `https://svatlas.io/mcp` returns 401 with `WWW-Authenticate: Bearer resource_metadata="https://svatlas.io/.well-known/oauth-protected-resource/mcp"`. That document names the authorization server, whose metadata is at https://svatlas.io/.well-known/oauth-authorization-server.
2. **Register.** POST your redirect URIs to https://svatlas.io/oauth/register (RFC 7591). Loopback `http` on any port and any `https` URI are accepted; the client is public (`token_endpoint_auth_method: none`).
3. **Authorize.** Send the person to https://svatlas.io/oauth/authorize with PKCE (`S256`) and scope `atlas`. They sign in with Google and click Allow. The redirect carries `code`, `state`, and `iss` (RFC 9207).
4. **Exchange.** POST the code and verifier to https://svatlas.io/oauth/token. You get a 1-hour access token and a 90-day refresh token; refreshing rotates both.
5. **Use.** Send `Authorization: Bearer <token>` on every `/mcp` request.
6. **Revocation.** The person can disconnect the agent in Settings → Agents. The next call gets 401 and the refresh token stops working; start again at step 3.

Support: support@getrush.ai.
