Skip to main content
Fincept MCP uses OAuth 2.1. Your client never sees your password; it receives tokens that work only on the MCP endpoint.

Sign-in flow

1

The client registers and opens the browser

On first connect the server answers 401 with a pointer to its OAuth metadata. The client registers itself and opens fincept.in/enterprise/connect.
2

You sign in and approve

Signed out, you sign in to your Fincept account first and land back on the request. The page shows which app is asking and where it will return. Select Authorize or Decline.
3

The client receives tokens

The browser returns to the client (a local port for terminal agents, an app link for editors). The client exchanges the one-time code for tokens and connects.
Approval needs an active Exclusive Pro plan. On another plan the connect page explains what is required instead of offering Authorize.

Token lifetimes

Every request is also checked live: if your plan lapses or your password changes, the next request is refused.

Revoke access

Removing a server from a client’s config does not end its sign-in on Fincept; sign out first.

Tokens are scoped

  • An MCP token works only at https://enterprise.fincept.in/mcp. It cannot call the Fincept API used by the terminal.
  • A terminal or website token is refused at the MCP endpoint.
  • The only scope is mcp: the agent can do what your plan allows through the tools listed in this documentation, and nothing that moves real money.