> ## Documentation Index
> Fetch the complete documentation index at: https://docs.liftx.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Preview MCP authorization

> Validate and normalize the OAuth client request without creating a grant.

<Note>MCP is implemented locally and is not production active. These synthetic examples do not announce availability or submit requests.</Note>

## Authorization

Authenticated Liftx Settings session. API keys, TradingView capabilities and MCP access tokens cannot authenticate this application route. Use [Settings → Integrations](https://app.liftx.io/settings/integrations); the public API hostname does not provide session access.

## Behavior

The response contains `client_name`, normalized `authorization`, `allowed_scopes` and the exact `resource`. Preview validates the callback/client pairing, resource, state and PKCE challenge. It does not create a credential, issue a code or consume fresh approval. Client labels come from callback policy; a local callback does not attest a provider identity.

## JSON body example

This is a synthetic local-client shape. The actual client owns registration, callback, state and PKCE challenge. Do not manually construct consent from a chat or substitute a different client request. Fixed timestamps are illustrative.

```json theme={null}
{
  "authorization": {
    "client_id": "lx_mcp_client_WyJodHRwOi8vMTI3LjAuMC4xOjU0MzIxL2NhbGxiYWNrIl0",
    "redirect_uri": "http://127.0.0.1:54321/callback",
    "response_type": "code",
    "resource": "https://mcp.liftx.io/mcp",
    "code_challenge": "E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM",
    "code_challenge_method": "S256",
    "state": "SYNTHETIC_CLIENT_STATE",
    "scope": "read"
  }
}
```

## Response and errors

Success is `200` with normalized metadata. An omitted/empty authorization `scope` defaults to `read`; duplicate or unknown scope names are rejected. The allowed scopes are the OAuth client’s request, not permissions already granted to it. Preview is outside the issuance limiter and retains bounded request/concurrency admission.

MCP activation is required. When disabled, `503` uses `{error:"temporarily_unavailable",error_description,iss}`; other validation/admission failures retain the documented integration error envelope. Check status and content type. Unknown/duplicate JSON fields and compressed bodies are rejected; request size is limited to 256 KiB.

See [Settings contract](/api/settings-contract) and [MCP authorization](/mcp/overview).


## OpenAPI

````yaml api/openapi.json POST /integrations/mcp/preview
openapi: 3.1.0
info:
  title: Liftx integrations
  version: 1.0.0
  description: >-
    Preview contract for the Liftx API, TradingView webhook and session-owned
    integration settings. Production availability is pending activation and
    release qualification. External access requires Pro or trial entitlement and
    is unmetered within bounded resource limits. Receipt acceptance does not
    confirm execution completion. MCP is not active.
servers:
  - url: https://api.liftx.io
security: []
paths:
  /integrations/mcp/preview:
    post:
      summary: Preview and normalize an MCP authorization request
      description: >-
        Session-owned Liftx Settings contract. Ordinary API keys, TradingView
        capabilities and MCP access tokens cannot authenticate this route. Use
        the authenticated Settings application; the public API hostname does not
        grant session access. Validates the exact public-client callback,
        resource, state, scope and PKCE challenge and returns normalized
        authorization metadata. Creates no credential or code and consumes no
        fresh approval. Client name derives from the reviewed callback policy;
        the local-client label is not verified provider identity. MCP activation
        is required. JSON is strict, uncompressed and limited to 256 KiB.
      operationId: post_integrations_mcp_preview
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                authorization:
                  $ref: '#/components/schemas/OAuthAuthorization'
              required:
                - authorization
              additionalProperties: false
            examples:
              synthetic:
                summary: Synthetic local-client authorization preview
                description: >-
                  Synthetic documentation data, not an account snapshot, valid
                  credential or production-availability assertion. Fixed times,
                  IDs and callback state are illustrative; use the OAuth client
                  request in the real Settings flow.
                value:
                  authorization:
                    client_id: >-
                      lx_mcp_client_WyJodHRwOi8vMTI3LjAuMC4xOjU0MzIxL2NhbGxiYWNrIl0
                    redirect_uri: http://127.0.0.1:54321/callback
                    response_type: code
                    resource: https://mcp.liftx.io/mcp
                    code_challenge: E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM
                    code_challenge_method: S256
                    state: SYNTHETIC_CLIENT_STATE
                    scope: read
      responses:
        '200':
          description: Normalized metadata; no authorization grant is created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MCPPreviewResponse'
              examples:
                synthetic:
                  summary: Synthetic normalized preview; no grant issued
                  description: >-
                    Synthetic documentation data, not an account snapshot, valid
                    credential or production-availability assertion. Fixed
                    times, IDs and callback state are illustrative; use the
                    OAuth client request in the real Settings flow.
                  value:
                    client_name: Local MCP client
                    authorization:
                      client_id: >-
                        lx_mcp_client_WyJodHRwOi8vMTI3LjAuMC4xOjU0MzIxL2NhbGxiYWNrIl0
                      redirect_uri: http://127.0.0.1:54321/callback
                      response_type: code
                      resource: https://mcp.liftx.io/mcp
                      code_challenge: E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM
                      code_challenge_method: S256
                      state: SYNTHETIC_CLIENT_STATE
                      scope: read
                    allowed_scopes:
                      - read
                    resource: https://mcp.liftx.io/mcp
        '503':
          description: >-
            MCP disabled returns the OAuth-shaped availability error; temporary
            internal admission failure retains the integration error shape
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/MCPOAuthUnavailable'
                  - $ref: '#/components/schemas/Error'
        default:
          description: >-
            Integration errors use Error; existing trading handlers retain their
            own JSON or text/plain error codec. Inspect status and content type.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
            text/plain:
              schema:
                type: string
      security:
        - SessionBearer: []
components:
  schemas:
    OAuthAuthorization:
      type: object
      properties:
        client_id:
          type: string
          maxLength: 3072
          pattern: ^lx_mcp_client_[A-Za-z0-9_-]+$
          description: >-
            Required. Exact opaque identifier returned by public OAuth client
            registration. Server revalidates its canonical callback set; do not
            invent an ID or treat it as a secret.
        redirect_uri:
          type: string
          format: uri
          maxLength: 512
          description: >-
            Required. Exact callback registered in client_id. Supported
            callbacks: https://claude.ai/api/mcp/auth_callback;
            https://chatgpt.com/connector_platform_oauth_redirect;
            https://chatgpt.com/connector/oauth/{identifier} with 1–128 ASCII
            letters/digits, hyphens or underscores; or
            http://localhost:{port}/callback / http://127.0.0.1:{port}/callback
            with port 1024–65535. No userinfo, query, fragment or escaped path.
        response_type:
          type: string
          const: code
        resource:
          type: string
          format: uri
          pattern: >-
            ^[hH][tT][tT][pP][sS]://[mM][cC][pP]\.[lL][iI][fF][tT][xX]\.[iI][oO]/mcp$
          description: >-
            Required. https://mcp.liftx.io/mcp with no port, credentials, query,
            fragment or escaped path. Scheme/hostname case is normalized; the
            path is exact.
        code_challenge:
          type: string
          minLength: 43
          maxLength: 43
          pattern: ^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$
          description: >-
            Required. Canonical unpadded base64url encoding of the 32-byte
            SHA-256 PKCE challenge. The client retains the verifier; do not send
            it to this Settings route.
        code_challenge_method:
          type: string
          const: S256
        state:
          type: string
          minLength: 1
          maxLength: 1024
          not:
            pattern: '[\u0000\r\n]'
          description: >-
            Required. Client-owned opaque state, 1–1024 UTF-8 bytes; NUL/CR/LF
            are rejected. Returned unchanged to the exact callback.
        scope:
          type: string
          default: read
          description: >-
            Optional. Whitespace-separated requested scopes: read,
            positions:open, positions:modify, positions:terminate,
            templates:write. At most five distinct scopes; duplicates/unknown
            values are rejected. Omitted or empty defaults to read. Preview
            returns a sorted, space-separated value.
      required:
        - client_id
        - redirect_uri
        - response_type
        - resource
        - code_challenge
        - code_challenge_method
        - state
      additionalProperties: false
    MCPPreviewResponse:
      type: object
      properties:
        client_name:
          type: string
          enum:
            - Claude
            - ChatGPT
            - Local MCP client
        authorization:
          allOf:
            - $ref: '#/components/schemas/OAuthAuthorization'
            - required:
                - scope
              properties:
                resource:
                  const: https://mcp.liftx.io/mcp
        allowed_scopes:
          type: array
          minItems: 1
          maxItems: 5
          uniqueItems: true
          items:
            type: string
            enum:
              - read
              - positions:open
              - positions:modify
              - positions:terminate
              - templates:write
        resource:
          type: string
          const: https://mcp.liftx.io/mcp
      required:
        - client_name
        - authorization
        - allowed_scopes
        - resource
      additionalProperties: false
    MCPOAuthUnavailable:
      type: object
      properties:
        error:
          type: string
          const: temporarily_unavailable
        error_description:
          type: string
        iss:
          type: string
          const: https://mcp.liftx.io
      required:
        - error
        - error_description
        - iss
      additionalProperties: false
    Error:
      type: object
      properties:
        success:
          const: false
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
          required:
            - code
            - message
          additionalProperties: false
      required:
        - success
        - error
      additionalProperties: false
  securitySchemes:
    SessionBearer:
      type: http
      scheme: bearer
      bearerFormat: existing authenticated Liftx session

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.