https://api.runflow.ai/connect) uses three OAuth 2.1 scopes. Your Claude client requests scopes when it connects, and each tool checks the scopes in your token.
Separately from scopes, every tool is annotated as read-only or changes data. Claude runs read-only tools without asking and asks you to confirm each tool that changes data. See Public tools.
Which scopes a client gets
- Clients registered through Dynamic Client Registration (RFC 7591) without a
scopefield getmcp:read mcp:write. - A client that lists
mcp:adminwhen it registers gets it too. You grant it when you sign in.
Tokens
Access tokens are RS256 JWTs signed by Runflow. They expire after one hour and are refreshed automatically. Revoking a client in Runflow invalidates every access token it issued, immediately. Public keys are published athttps://api.runflow.ai/.well-known/jwks.json. Token claims: