Sign-in and tokens

API tokens for your own scripts and agents, OAuth for the apps people connect, and the limits both can carry.

API tokens
abt_…
Apps
OAuth 2.1, PKCE
Scopes
files:read to full

API tokens#

Make one under API tokens in the app. fffd login makes its own, named FFFD CLI. A token is shown once, when it's made. We keep only a hash of it, so a lost token can't be shown again: make a new one.

An example token
abt_0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefg1mOR8O

Every token starts with abt_ and ends in a checksum. A mistyped one is turned away before anything is looked up, and a leaked one is easy for secret scanners to spot.

Limits#

A token without limits reaches everything its owner can, from anywhere: the CLI, the MCP server on your machine, the HTTP API and the hosted server. Give it limits and it works only through the hosted server, which holds every call to them.

LevelScopeReaches
Readfiles:readReachesFind, open and link to your files, and see who opened them.
Organizefiles:organizeReachesAlso tag, move, add and arrange files. Nothing it does shows to anyone else, and nothing gets deleted.
Sharefiles:shareReachesAlso make files public, send them out for review, collect files from anyone, and save files from links. Nothing gets deleted.
Everythingfiles:fullReachesAlso delete files.

A token can also be held to one folder and the folders inside it, and set to stop working on a date. Delete the folder and the token reaches nothing, rather than more.

Sessions#

A token is traded for a session before anything is called. The CLI, the MCP server on your machine and your own code get one that lasts a day, and trade again when it runs out. See Authenticate.

The hosted server keeps the sessions itself and checks back every minute, so a token you turn off stops working there within a minute.

Apps and OAuth#

Apps that connect people's drives, like Claude and ChatGPT, sign in with OAuth 2.1 at the hosted server. They register themselves, send the person to the drive to choose what to allow, and trade the code for tokens. A person can always give an app less than it asks for, never more.

Where
Discovery/.well-known/oauth-authorization-server
Resources/.well-known/oauth-protected-resource/mcp
Register/register
Authorize/authorize
Tokens/token
Revoke/revoke

Asking for access#

The link an app sends people to
https://mcp.freakingfast.io/authorize
  ?response_type=code
  &client_id=…
  &redirect_uri=https://your-app.example/callback
  &code_challenge=…&code_challenge_method=S256
  &scope=files:organize
  &resource=https://mcp.freakingfast.io/mcp
  &state=…
  • PKCE with S256 is required. A link without it stops on a page rather than going back to the app.
  • scope is the most the app wants: files:read, files:organize, files:share or files:full. Leave it out and the person chooses freely.
  • resource is /mcp or /a2a on the same server.
  • The code lasts five minutes. Access tokens last an hour, and each refresh hands back a new refresh token.
  • The code only goes back to the app through the browser that started signing in.

Telling tokens apart#

Every secret we hand out says what it is, and ends in a checksum.

Starts withIs
abt_An API token.
abo_An app’s OAuth access token.
abr_An app’s refresh token.
abc_A sign-in code, on its way back to an app.

Turning things off#

Disconnect an app, or turn off or delete a token, under API tokens in the app. Through the hosted server it stops within a minute, and anything it had waiting ends. A session the CLI already holds runs until it expires, at most a day.