Skip to content

Authentication

ScopeKite owns its auth (email + password via Better Auth, wrapped behind an internal adapter — ADR-007).

  • Sign-up requires email verification (delivered via the transactional email pipeline; in local dev, Mailpit catches everything).
  • Web uses an HttpOnly, SameSite=Lax first-party cookie behind a same-origin proxy; mobile uses bearer tokens. ScopeKite also acts as an OAuth 2.1 provider for its bounded MCP assistant surface; it does not offer social login.
  • Password reset and session management are self-serve: Settings → “Your sessions” lists devices and revokes one or all others immediately.
  • Sign-up and sensitive endpoints are rate-limited per IP and per account.

Authorization is separate from authentication: membership and roles are enforced per-workspace on every request (Security and tenancy).

The hosted MCP connection signs in with the same ScopeKite account. ScopeKite asks the person to choose one of their active owner, admin, or member workspaces. The selected workspace is bound server-side to the grant; it does not come from a tool argument and workspace slugs are not published in OAuth discovery. Requested read and write access is shown separately on the consent screen before approval and is checked again by the server.

If no workspace is offered, create a workspace or accept an invitation as an owner, admin, or member, then start the connection again. Guests cannot connect an assistant. Operators can still disable the whole MCP surface with the deployment kill switch.