client_id. Recoup retrieves that document and validates the client’s callbacks before asking you to approve access.
Use the same MCP server URL: https://api.recoupable.dev/mcp. A compatible client can discover CIMD through client_id_metadata_document_supported: true in Recoup’s authorization-server metadata. No vendor-specific registration or callback allowlist is needed.
Access and trust
CIMD uses the same personal-account permissions and consent as DCR. It does not bypass sign-in, PKCE, tool scope checks, grant expiry, or disconnection. Existing DCR connections continue to work. A client name or logo is self-declared metadata, not proof of vendor endorsement. Check the client identity and requested permissions before allowing access. Publishing a document does not authorize its client to access your account.Client requirements
- Serve JSON with HTTP 200 over public HTTPS on port 443. Redirects are rejected.
- Set
client_idto the exact document URL and includeclient_nameandredirect_uris. - Use a document URL with an explicit path and without credentials, fragments, or dot path segments.
- Use authorization code flow with PKCE S256 and Recoup’s
mcp:read/mcp:writescopes. - Public clients should set
token_endpoint_auth_methodtonone. Never publish client secrets or private keys. - Register exact callbacks. Hosted HTTP callbacks are rejected; native loopback callbacks support dynamic ports.
localhostand127.0.0.1remain different hosts.
no-store, no-cache, absent freshness information, or expired freshness causes a new fetch. A failed refresh does not reuse expired metadata.
