MCP documentation menu

Authentication

The DataPulse MCP server uses OAuth 2.1 for authentication.

OAuth Flow

  1. Client initiates authorization at the authorization endpoint
  2. User authenticates and grants permissions
  3. Client receives authorization code
  4. Client exchanges code for access token
  5. Client includes token in MCP requests

Required Scopes

Tools require functional scopes based on their category. The help, AGB, and health tools require no scope.

ScopeDescription
datapulse:dnsDNS lookup tools (DataPulse history/search/techsim/neighborhood/regclusters/registrar, live DNS/RDAP), DisputeDB
datapulse:scrapeWeb scraping tools (submit, bulk, result, bulk_results, list, domain_overview)
datapulse:testTest/diagnostic tools (echo, timestamp, slow, panic)

Token Usage

Include your access token in MCP requests. The server validates tokens and extracts the user identity from the JWT sub claim.

Token Refresh

Access tokens expire. Use your refresh token to obtain new access tokens before expiry.

Error Handling

401 Unauthorized

Your token is missing, invalid, or expired. Re-authenticate or refresh your token.

403 Forbidden

Your token is valid but lacks required scopes. Request additional scopes during authorization.

Security Best Practices

  1. Never share tokens - Treat access tokens like passwords
  2. Use short expiry - Prefer short-lived access tokens with refresh
  3. Rotate secrets - Periodically rotate client secrets
  4. HTTPS only - Never transmit tokens over unencrypted connections

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="authentication").