Skip to main content
POST
Approve an MCP OAuth grant with exact fresh account proof
MCP is implemented locally and is not production active. These synthetic examples do not announce availability or submit requests.

Authorization

Authenticated Liftx Settings session. API keys, TradingView capabilities and MCP access tokens cannot authenticate this application route. Use Settings → Integrations; the public API hostname does not provide session access.

Behavior

First start fresh authentication with purpose:"mcp" and the same complete MCPConsentRequest, then verify the offered password/Apple proof and MFA when required. Submit the unchanged request with that operation UUID before the five-minute approval expires. The grant requires current Pro/trial entitlement, one to 32 owned active links, a subset of requested scopes and an expiry within 30 days. Any selected position/template write scope requires trading_consent:true. Omitted instrument_ids permits all instruments on the selected links; otherwise exact canonical IDs are required.

JSON body example

This is a synthetic local-client shape. The actual client owns registration, callback, state and PKCE challenge. Do not manually construct consent from a chat or substitute a different client request. Fixed timestamps are illustrative.

Response and errors

Success is 201 with credential metadata of kind mcp and a sensitive redirect_url containing the one-time code, original state and issuer. The code lasts two minutes; the OAuth client exchanges it with its retained verifier. No access token, refresh token or ordinary API key is returned here. Never log or paste the callback URL into chat. An identical committed retry is 409 OAUTH_APPROVAL_CONSUMED; it cannot recover the code. After an ambiguous response inspect connection metadata and deliberately restart OAuth rather than replaying approval. The operation shares the 12-requests/minute/IP issuance limiter. MCP activation is required. When disabled, 503 uses {error:"temporarily_unavailable",error_description,iss}; other validation/admission failures retain the documented integration error envelope. Check status and content type. Unknown/duplicate JSON fields and compressed bodies are rejected; request size is limited to 256 KiB. See Settings contract and MCP authorization.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
operation_id
string<uuid>
required

Required nonzero UUID of the approved mcp-purpose request for this same account session.

request
object
required

Response

New MCP credential metadata and sensitive one-time callback URL

credential
object
required
redirect_url
string<uri>
required

Exact registered callback with one-time code, original state and iss=https://mcp.liftx.io. The code expires after two minutes and is exchanged by the OAuth client with PKCE. Sensitive: never log, paste into chat or repeat after an ambiguous response.