[{"data":1,"prerenderedAt":516},["ShallowReactive",2],{"navigation_docs":3,"-mcp-authentication":54,"-mcp-authentication-surround":511},[4,18,40],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,10,14],{"title":5,"path":6,"stem":7},{"title":11,"path":12,"stem":13},"Console Tour","\u002Fgetting-started\u002Fconsole-tour","1.getting-started\u002F2.console-tour",{"title":15,"path":16,"stem":17},"The Free Audit","\u002Fgetting-started\u002Ffree-audit","1.getting-started\u002F3.free-audit",{"title":19,"path":20,"stem":21,"children":22},"MCP Server","\u002Fmcp","2.mcp\u002F1.index",[23,24,28,32,36],{"title":19,"path":20,"stem":21},{"title":25,"path":26,"stem":27},"Setup","\u002Fmcp\u002Fsetup","2.mcp\u002F2.setup",{"title":29,"path":30,"stem":31},"Available Tools","\u002Fmcp\u002Favailable-tools","2.mcp\u002F3.available-tools",{"title":33,"path":34,"stem":35},"Authentication","\u002Fmcp\u002Fauthentication","2.mcp\u002F4.authentication",{"title":37,"path":38,"stem":39},"Troubleshooting","\u002Fmcp\u002Ftroubleshooting","2.mcp\u002F5.troubleshooting",{"title":41,"path":42,"stem":43,"children":44},"API Reference","\u002Fapi","3.api\u002F1.index",[45,46,50],{"title":41,"path":42,"stem":43},{"title":47,"path":48,"stem":49},"Bulk CSV","\u002Fapi\u002Fbulk-csv","3.api\u002F2.bulk-csv",{"title":51,"path":52,"stem":53},"Outbound Webhooks","\u002Fapi\u002Foutbound-webhooks","3.api\u002F3.outbound-webhooks",{"id":55,"title":33,"body":56,"description":504,"extension":505,"links":506,"meta":507,"navigation":508,"path":34,"seo":509,"stem":35,"__hash__":510},"docs\u002F2.mcp\u002F4.authentication.md",{"type":57,"value":58,"toc":489},"minimark",[59,63,118,126,181,196,203,227,231,241,317,321,324,388,391,395,402,425,429,439,443,473,477],[60,61,62],"p",{},"PlaceOptimizer has two MCP surfaces with two different trust models. Which one\napplies depends on which endpoint you call.",[64,65,66,82],"table",{},[67,68,69],"thead",{},[70,71,72,76,79],"tr",{},[73,74,75],"th",{},"Surface",[73,77,78],{},"URL",[73,80,81],{},"Auth",[83,84,85,103],"tbody",{},[70,86,87,94,100],{},[88,89,90],"td",{},[91,92,93],"strong",{},"Public endpoint",[88,95,96],{},[97,98,99],"code",{},"https:\u002F\u002Fapp.placeoptimizer.com\u002Fmcp",[88,101,102],{},"None for discovery + 3 public tools; OAuth 2.1 Bearer JWT for all 8 tools",[70,104,105,110,115],{},[88,106,107],{},[91,108,109],{},"Console-internal",[88,111,112],{},[97,113,114],{},"https:\u002F\u002Fapp.placeoptimizer.com\u002Fapi\u002Fv1\u002Fmcp",[88,116,117],{},"PlaceOptimizer session (active org, member role)",[119,120,122,123,125],"h2",{"id":121},"public-endpoint-oauth-protected-mcp","Public endpoint — OAuth-protected (",[97,124,20],{},")",[60,127,128,130,131,134,135,138,139,138,142,145,146,138,149,152,153,156,157,160,161,164,165,138,168,138,171,152,174,138,177,180],{},[97,129,99],{}," is the ",[91,132,133],{},"dual-auth discovery surface",".\nIts discovery methods (",[97,136,137],{},"server\u002Fdiscover",", ",[97,140,141],{},"initialize",[97,143,144],{},"tools\u002Flist",", …) and\nthree read-only tools (",[97,147,148],{},"ping_console",[97,150,151],{},"get_audit_overview",",\n",[97,154,155],{},"get_public_endpoints",") are served to ",[91,158,159],{},"any caller with no authentication",".\nA valid ",[91,162,163],{},"OAuth 2.1 Bearer JWT"," unlocks the five tenant tools\n(",[97,166,167],{},"list_locations",[97,169,170],{},"get_location_metrics",[97,172,173],{},"list_location_reviews",[97,175,176],{},"list_location_posts",[97,178,179],{},"get_org_info",") on the same endpoint.",[60,182,183,184,187,188,191,192,195],{},"A tenant tool call without a valid token is rejected with ",[91,185,186],{},"401\nUnauthorized"," and a ",[97,189,190],{},"WWW-Authenticate: Bearer resource_metadata=…"," challenge\npointing at the RFC 9728 protected-resource metadata — which is how an MCP\nclient learns where to authenticate. See\n",[193,194,29],"a",{"href":30}," for what each surface exposes.",[119,197,199,200,125],{"id":198},"console-internal-endpoint-session-apiv1mcp","Console-internal endpoint — session (",[97,201,202],{},"\u002Fapi\u002Fv1\u002Fmcp",[60,204,205,207,208,211,212,215,216,219,220,223,224,226],{},[97,206,114],{}," is the console-internal path used\nby the operator console itself. It sits under ",[97,209,210],{},"\u002Fapi\u002Fv1",", so the console's\n",[91,213,214],{},"session guard"," runs first: the request must carry a valid PlaceOptimizer\nsession cookie, belong to a user with an ",[91,217,218],{},"active organization",", and the\nuser must hold at least the ",[91,221,222],{},"member"," role. Third-party connectors do not\nuse this path — they authenticate to ",[97,225,20],{}," through the OAuth flow below.",[119,228,230],{"id":229},"the-oauth-21-flow","The OAuth 2.1 flow",[60,232,233,234,236,237,240],{},"Third-party clients (Claude, ChatGPT, Cursor, CLI tools) authenticate to\n",[97,235,20],{}," with a standard ",[91,238,239],{},"OAuth 2.1 \u002F OIDC"," authorization server run by the\nconsole. The flow is live and fully automatic from the client's perspective:",[242,243,244,263,269,287,300],"ol",{},[245,246,247,250,251,254,255,258,259,262],"li",{},[91,248,249],{},"Discovery."," The client fetches the RFC 9728 protected-resource metadata\nat\n",[97,252,253],{},"https:\u002F\u002Fapp.placeoptimizer.com\u002F.well-known\u002Foauth-protected-resource",",\nwhich points it at the authorization-server metadata at\n",[97,256,257],{},"https:\u002F\u002Fapp.placeoptimizer.com\u002F.well-known\u002Foauth-authorization-server","\n(issuer ",[97,260,261],{},"https:\u002F\u002Fapp.placeoptimizer.com\u002Fapi\u002Fv1\u002Fauth",").",[245,264,265,268],{},[91,266,267],{},"Dynamic client registration (DCR)."," Public clients register themselves\nper RFC 7591 at the registration endpoint — no developer portal, no\npre-shared secret.",[245,270,271,274,275,278,279,282,283,286],{},[91,272,273],{},"Authorization + consent."," The client opens a browser window to the\nPlaceOptimizer sign-in (",[97,276,277],{},"\u002Flogin",") and consent (",[97,280,281],{},"\u002Fconsent",") pages, where you\napprove the requested scopes. ",[91,284,285],{},"PKCE"," (RFC 7636) is required.",[245,288,289,292,293,296,297,299],{},[91,290,291],{},"Token."," The client exchanges the authorization code for a short-lived\n",[91,294,295],{},"EdDSA JWT"," access token with audience\n",[97,298,99],{}," (the RFC 8707 resource indicator)\nplus a refresh token.",[245,301,302,308,309,312,313,316],{},[91,303,304,305,307],{},"Bearer on ",[97,306,20],{},"."," The client sends the token as\n",[97,310,311],{},"Authorization: Bearer \u003Ctoken>",". The resource server verifies the\nsignature against the public JWKS at ",[97,314,315],{},"\u002Fapi\u002Fv1\u002Fauth\u002Fjwks"," and enforces the\nissuer and audience strictly; a verified token unlocks all eight tools.",[119,318,320],{"id":319},"scopes","Scopes",[60,322,323],{},"The consent screen and the server's scope allow-list cover five scopes:",[64,325,326,336],{},[67,327,328],{},[70,329,330,333],{},[73,331,332],{},"Scope",[73,334,335],{},"What it grants",[83,337,338,348,358,368,378],{},[70,339,340,345],{},[88,341,342],{},[97,343,344],{},"openid",[88,346,347],{},"Verify your PlaceOptimizer account identity",[70,349,350,355],{},[88,351,352],{},[97,353,354],{},"profile",[88,356,357],{},"Read your name and avatar",[70,359,360,365],{},[88,361,362],{},[97,363,364],{},"email",[88,366,367],{},"Read your email address",[70,369,370,375],{},[88,371,372],{},[97,373,374],{},"offline_access",[88,376,377],{},"Stay connected while you are away (refresh token)",[70,379,380,385],{},[88,381,382],{},[97,383,384],{},"placeoptimizer",[88,386,387],{},"Read your locations, metrics, reviews and posts",[60,389,390],{},"Only the scopes you approve are granted, and the access token carries exactly\nthe granted set.",[119,392,394],{"id":393},"device-flow","Device flow",[60,396,397,398,401],{},"CLI-style clients that cannot open a browser use the ",[91,399,400],{},"RFC 8628 device flow",".\nThe client asks the authorization server for a device code, shows you a\nverification URL and code, and polls for its token. On PlaceOptimizer:",[403,404,405,416,422],"ul",{},[245,406,407,408,411,412,415],{},"Enter the code at ",[97,409,410],{},"https:\u002F\u002Fapp.placeoptimizer.com\u002Fdevice","\n(",[97,413,414],{},"\u002Fdevice?user_code=ABCD-1234"," pre-fills it for one-click flows).",[245,417,418,419,262],{},"Approve (or deny) the request at the device-approval page\n(",[97,420,421],{},"\u002Fdevice\u002Fapprove",[245,423,424],{},"The code expires after 15 minutes; the client polls every 5 seconds.",[119,426,428],{"id":427},"refreshing-tokens","Refreshing tokens",[60,430,431,432,434,435,438],{},"Because the flow includes ",[97,433,374],{},", every grant issues a ",[91,436,437],{},"refresh\ntoken"," alongside the short-lived access token. The client refreshes\nautomatically — the access token is renewed without another consent screen.\nNo action is needed from you until you revoke the grant.",[119,440,442],{"id":441},"revoking-access","Revoking access",[403,444,445,455,464],{},[245,446,447,450,451,454],{},[91,448,449],{},"OAuth grants:"," open ",[91,452,453],{},"Settings → Connected apps"," in the console. It\nlists every app you have granted access to; revoking an app there revokes\nthe grant and invalidates its refresh and access tokens — the app's next\ntool call returns 401 until it re-authorizes.",[245,456,457,460,461,307],{},[91,458,459],{},"Console session:"," sign out, or revoke the active session from\n",[91,462,463],{},"Settings → Devices",[245,465,466,469,470,307],{},[91,467,468],{},"Google connection:"," if you want PlaceOptimizer to stop reading your GBP\ndata, disconnect the Google account from ",[91,471,472],{},"Settings → Google Account",[119,474,476],{"id":475},"next-steps","Next steps",[403,478,479,484],{},[245,480,481,483],{},[193,482,37],{"href":38}," — 401s, consent loops, and audience errors",[245,485,486,488],{},[193,487,25],{"href":26}," — connect a client, step by step",{"title":490,"searchDepth":491,"depth":491,"links":492},"",3,[493,496,498,499,500,501,502,503],{"id":121,"depth":494,"text":495},2,"Public endpoint — OAuth-protected (\u002Fmcp)",{"id":198,"depth":494,"text":497},"Console-internal endpoint — session (\u002Fapi\u002Fv1\u002Fmcp)",{"id":229,"depth":494,"text":230},{"id":319,"depth":494,"text":320},{"id":393,"depth":494,"text":394},{"id":427,"depth":494,"text":428},{"id":441,"depth":494,"text":442},{"id":475,"depth":494,"text":476},"How PlaceOptimizer MCP authentication works — public discovery tools, the live OAuth 2.1 flow for third-party clients, and the console-internal session path.","md",null,{},true,{"title":33,"description":504},"7rVW07OTcj2uDpQGkrOXpZxXToXqAE_hbKA-NA2YfNg",[512,514],{"title":29,"path":30,"stem":31,"description":513,"children":-1},"Full reference for all 8 PlaceOptimizer MCP tools — public discovery tools and authenticated console tools with inputs and outputs.",{"title":37,"path":38,"stem":39,"description":515,"children":-1},"Common PlaceOptimizer MCP issues — 401s, missing tools, connection failures — and how to fix them.",1786649635795]