generated: '2026-09-05' method: probed source: >- https://mcp.1up.ai/.well-known/oauth-authorization-server ; https://mcp.1up.ai/.well-known/oauth-protected-resource ; https://help.1up.ai/en/articles/14304740-mcp docs: https://help.1up.ai/en/articles/14304740-mcp note: >- Derived from probed RFC 8414 / RFC 9728 discovery documents and observed 401 responses, not from an OpenAPI — 1up publishes no OpenAPI. Two distinct auth surfaces exist and they are not the same thing: the public MCP server (OAuth 2.1) and the platform REST host api.1upapi.com (undocumented, token-authenticated, Django REST Framework). summary: types: [oauth2] api_key_in: [] oauth2_flows: [authorizationCode] bearer_methods: [header] pkce: [S256] dynamic_client_registration: true identity_provider: Auth0 (1up-app.us.auth0.com) human_sso: >- Single Sign-On is a paid platform feature from the Starter tier upward (https://help.1up.ai/en/articles/13401537-enabling-single-sign-on-sso). schemes: - name: 1up MCP OAuth 2.1 type: oauth2 applies_to: https://mcp.1up.ai/mcp sources: [well-known/1up-oauth-authorization-server.json, well-known/1up-oauth-protected-resource.json] issuer: https://mcp.1up.ai flows: - flow: authorizationCode authorizationUrl: https://mcp.1up.ai/authorize tokenUrl: https://mcp.1up.ai/token registrationUrl: https://mcp.1up.ai/register code_challenge_methods_supported: [S256] grant_types_supported: [authorization_code, refresh_token] response_types_supported: [code] token_endpoint_auth_methods_supported: [none] scopes: [openid, profile, email, offline_access] public_client_id: TAWQL8mbs0eHLzaBaxV3Va5vH6qal4Wq public_client_id_note: >- Published by the provider in both the discovery document and the copy-paste Claude Code config in their own docs. It is a public OAuth client identifier, not a secret. protected_resource: resource: https://mcp.1up.ai/mcp authorization_servers: [https://mcp.1up.ai] bearer_methods_supported: [header] resource_name: 1up MCP Server challenge_observed: url: https://mcp.1up.ai/mcp http_status: 401 www_authenticate: Bearer body: '{"error":"unauthorized","error_description":"Missing Authorization header"}' - name: 1up platform API token type: http scheme: bearer applies_to: https://api.1upapi.com/api/v1/ documented: false sources: [pypi:1up-mcp==0.1.0 (oneup_mcp/api_client.py, oneup_mcp/config.py)] note: >- Not part of a public developer program. The base URL and Authorization-header behaviour are recorded here only because 1up's own published PyPI package names them; there is no public reference, no published spec and no self-service key issuance. The host answers an anonymous GET /api/v1/ with HTTP 401 and the Django REST Framework body {"detail":"Authentication credentials were not provided."}. Tokens are Auth0-issued (audience https://1up-app.us.auth0.com/api/v2/) and obtained via `1up-mcp auth login`. challenge_observed: url: https://api.1upapi.com/api/v1/ http_status: 401 body: '{"detail":"Authentication credentials were not provided."}'