> ## Documentation Index
> Fetch the complete documentation index at: https://docs.runflow.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Scopes

> OAuth scopes used by the Runflow connector for Claude

The Runflow connector (`https://api.runflow.ai/connect`) uses three OAuth 2.1 scopes. Your Claude client requests scopes when it connects, and each tool checks the scopes in your token.

| Scope | What it allows | Tools |
| - | - | - |
| `mcp:read` | Read everything in your workspace: agents, executions and traces, reviews, prompts, knowledge bases, connectors, credential metadata, triggers, LLM providers, dashboards, events and docs | 52 |
| `mcp:write` | Everything in `mcp:read`, plus creating, updating, deploying and running things: chat with an agent, execute a connector, deploy and promote agents, publish releases, manage reviews and dashboards | 44 more |
| `mcp:admin` | Everything in `mcp:write`, plus the `delete_*` tools | 13 more |

Separately from scopes, every tool is annotated as **read-only** or **changes data**. Claude runs read-only tools without asking and asks you to confirm each tool that changes data. See [Public tools](/mcp/public-tools).

## Which scopes a client gets

* Clients registered through Dynamic Client Registration (RFC 7591) without a `scope` field get `mcp:read mcp:write`.
* A client that lists `mcp:admin` when it registers gets it too. You grant it when you sign in.

## Tokens

Access tokens are RS256 JWTs signed by Runflow. They expire after one hour and are refreshed automatically. Revoking a client in Runflow invalidates every access token it issued, immediately.

Public keys are published at `https://api.runflow.ai/.well-known/jwks.json`. Token claims:

```json theme={null}
{
  "iss": "https://api.runflow.ai",
  "sub": "<runflow user id>",
  "aud": "https://api.runflow.ai/connect",
  "tenant_id": "<runflow workspace id>",
  "scopes": ["mcp:read", "mcp:write"],
  "client_id": "<registered client id>",
  "jti": "<token id>",
  "iat": 1760000000,
  "exp": 1760003600
}
```

## Endpoints

| Endpoint | URL |
| - | - |
| MCP server | `https://api.runflow.ai/connect` |
| Authorization server metadata | `https://api.runflow.ai/.well-known/oauth-authorization-server` |
| Protected resource metadata (RFC 9728) | `https://api.runflow.ai/.well-known/oauth-protected-resource` |
| JWKS | `https://api.runflow.ai/.well-known/jwks.json` |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.