Tálamo
    Tálamo MCPv1.3

    OAuth and authentication

    Tálamo uses OAuth 2.1 with PKCE. The client never receives your password or broker credentials.

    How it works

    1. 01

      The client discovers the endpoint's protected resource metadata and registers its identifier.

    2. 02

      You sign in to Tálamo and authorize the app on a Tálamo consent screen.

    3. 03

      The token is bound to the user and client; RLS reapplies isolation to every query.

    4. 04

      You can revoke access in Settings and that client's sessions stop working.

    http
    GET https://talamo.app/.well-known/oauth-protected-resource/mcp