# auth.md

This file tells AI agents how to get and use access to LottieFiles services. It is a companion to the OAuth metadata that the services publish themselves.

## LottieFiles MCP Server

- Endpoint: `https://mcp.lottiefiles.com/mcp`
- Transport: Streamable HTTP
- Protocol: OAuth 2.1 with PKCE (S256)
- Scope: `mcp:full`
- Access tokens: sent as `Authorization: Bearer <token>`; they expire after 10 minutes. Refresh tokens rotate.
- Dynamic client registration is supported.

### Step 1 — Fetch the protected resource metadata

```http
GET https://mcp.lottiefiles.com/.well-known/oauth-protected-resource
```

The response lists the authorization servers that can issue tokens for the MCP server.

### Step 2 — Fetch the authorization server metadata

```http
GET https://mcp.lottiefiles.com/.well-known/oauth-authorization-server
```

The response gives the endpoints:

- `authorization_endpoint`: `https://mcp.lottiefiles.com/authorize`
- `token_endpoint`: `https://mcp.lottiefiles.com/token`
- `registration_endpoint`: `https://mcp.lottiefiles.com/register`
- `revocation_endpoint`: `https://mcp.lottiefiles.com/revoke`

### Step 3 — Run the authorization code flow with PKCE

1. Register a client at the `registration_endpoint` (if your client does not do this for you).
2. Send the user to the `authorization_endpoint` with `response_type=code`, your `client_id`, a S256 `code_challenge`, and a `redirect_uri`.
3. Exchange the code at the `token_endpoint` with `grant_type=authorization_code` and your `code_verifier`.
4. Call the MCP endpoint with the access token in the `Authorization` header.

MCP clients such as Claude Code, Cursor, and VS Code perform all of these steps automatically. Approve access with your LottieFiles account in the browser window that opens on first use.

### Errors and revocation

- The server returns standard OAuth 2.1 error codes.
- To revoke access, call the `revocation_endpoint`, or remove the connection in your MCP client, or manage connected applications in your LottieFiles account settings.

## Scope and permissions

The MCP server has no static API keys. Every action runs with the permissions of the LottieFiles account that approved access. The single scope `mcp:full` grants the assistant the same access as the account owner.

Full security guidance: <https://docs.lottiefiles.com/en/platform/mcp/security>