generated: '2026-09-05' method: probed source: >- https://login.abatable.com/.well-known/openid-configuration and https://mcp.abatable.com/.well-known/oauth-protected-resource — fetched 2026-09-05. No OpenAPI exists in this repo, so nothing here is derived from a spec; every field below was read out of a discovery document the provider serves. docs: null docs_note: >- Abatable publishes no authentication documentation. There is no developer portal and no API reference; /developers on abatable.com is a marketing page for carbon PROJECT developers, not software developers. The auth model below is what the two live discovery surfaces disclose. summary: types: [oauth2, openIdConnect] api_key_in: [] oauth2_flows: [authorizationCode, clientCredentials, refreshToken, deviceCode, implicit, password, tokenExchange, jwtBearer] human_auth: OIDC via an Auth0 tenant on the custom domain login.abatable.com machine_auth: OAuth 2.0 via Cloudflare Access for the MCP endpoint two_independent_issuers: true note: >- The application and the MCP endpoint do NOT share an identity provider. app.abatable.com authenticates end users against Auth0 (issuer https://login.abatable.com/); mcp.abatable.com is gated by Cloudflare Access (issuer https://abatable.cloudflareaccess.com). An agent holding an application session token cannot call the MCP server with it. schemes: - name: Auth0 OIDC (end-user application sign-in) type: openIdConnect openIdConnectUrl: https://login.abatable.com/.well-known/openid-configuration issuer: https://login.abatable.com/ authorization_endpoint: https://login.abatable.com/authorize token_endpoint: https://login.abatable.com/oauth/token userinfo_endpoint: https://login.abatable.com/userinfo jwks_uri: https://login.abatable.com/.well-known/jwks.json device_authorization_endpoint: https://login.abatable.com/oauth/device/code revocation_endpoint: https://login.abatable.com/oauth/revoke registration_endpoint: https://login.abatable.com/oidc/register code_challenge_methods_supported: [S256, plain] token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt, none] id_token_signing_alg_values_supported: [HS256, RS256, PS256] dpop_signing_alg_values_supported: [ES256] observed_client_id_in_login_redirect: 4tYWXA9Pn1WFdKGAtSoKT9fsVwyupxMn observed_redirect_uri: https://app.abatable.com/api/auth/callback observed_connection: Username-Password-Authentication sources: [well-known/abatable-login-openid-configuration.json] - name: Cloudflare Access OAuth (MCP endpoint) type: oauth2 flows: - flow: authorizationCode authorizationUrl: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/authorization tokenUrl: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/token refreshUrl: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/token scopes: {} issuer: https://abatable.cloudflareaccess.com registration_endpoint: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/registration dynamic_client_registration: true code_challenge_methods_supported: [S256] protected_resource: https://mcp.abatable.com challenge_observed: 'HTTP 401 WWW-Authenticate: Bearer realm="OAuth", error="invalid_token", resource_metadata=...' rfc9728: true alternative_client: >- The Cloudflare Access protected-resource document also advertises `cloudflared access curl` as an interactive authentication method for CLI callers. sources: - well-known/abatable-mcp-oauth-authorization-server.json - well-known/abatable-mcp-oauth-protected-resource.json api_keys: supported: unknown note: No API key programme is documented or discoverable on any public Abatable surface.