generated: '2026-09-19' method: searched source: openapi/relmcrm-com-openapi.yml (components.securitySchemes bearerAuth + oauth2; root security[]) + https://relmcrm.com/docs (Base URL & auth; Connect via MCP; OAuth 2.1) + https://relmcrm.com/security (Secrets and keys) + well-known/relmcrm-com-oauth-authorization-server.json + live probes 2026-09-19 (401 on GET https://api.relmcrm.com/v1/schema; JSON-RPC -32001 + WWW-Authenticate on anonymous MCP tools/call; failed Task on anonymous A2A message/send) docs: https://relmcrm.com/docs summary: types: - http - oauth2 oauth2_flows: - authorizationCode one_credential_three_surfaces: The same bearer key (or OAuth access token) authenticates REST (https://api.relmcrm.com/v1), MCP (https://api.relmcrm.com/mcp) and A2A (https://api.relmcrm.com/a2a). anonymous_surface: MCP initialize and tools/list, the OpenAPI, llms.txt, the agent card, the MCP descriptor and both OAuth discovery documents are public; every data operation requires a credential. schemes: - name: bearerAuth type: http scheme: bearer header: 'Authorization: Bearer ' key_prefixes: live: relm_live_ test: relm_test_ minted_at: https://app.relmcrm.com/ (dashboard, "API keys" — live and test tabs) shown_once: true at_rest: SHA-256 hash; a lost key is rotated, never recovered (https://relmcrm.com/security) scoping: workspace-bound; the key decides test vs live mode and data never crosses recommended_for: servers and CI (docs); required for test mode description: Workspace-scoped API key. relm_live_... (live) or relm_test_... (free, isolated test mode). Mint at https://app.relmcrm.com/. failure: >- 401 application/problem+json code unauthorized — "Missing or invalid API key. Send `Authorization: Bearer relm_live_...`." (observed live) sources: - openapi/relmcrm-com-openapi.yml - https://relmcrm.com/docs - name: oauth2 type: oauth2 version: OAuth 2.1 issuer: https://api.relmcrm.com flows: - flow: authorizationCode authorizationUrl: https://api.relmcrm.com/oauth/authorize tokenUrl: https://api.relmcrm.com/oauth/token refreshUrl: https://api.relmcrm.com/oauth/token scopes: 1 pkce: S256 required refresh_tokens: yes, with rotation (docs) dynamic_client_registration: RFC 7591 at https://api.relmcrm.com/oauth/register (POST; GET returns 404) revocation: https://api.relmcrm.com/oauth/revoke token_endpoint_auth_methods: [none, client_secret_post, client_secret_basic] discovery: authorization_server: https://api.relmcrm.com/.well-known/oauth-authorization-server (well-known/relmcrm-com-oauth-authorization-server.json) protected_resource: https://api.relmcrm.com/.well-known/oauth-protected-resource (well-known/relmcrm-com-oauth-protected-resource.json) live_only: true live_only_note: OAuth grants act on live data; test mode stays API-key only (docs). recommended_for: end-user chat clients (Claude, ChatGPT) — "the client registers itself, you approve in a browser, and you never handle a secret" consent_screen: names the actual redirect destination and marks the app's self-declared name as unverified; anti-clickjacking protection; account creation and email confirmation inline (changelog v0.13.0–v0.15.0) connected_apps: listed in the dashboard; disconnecting revokes all access immediately (changelog v0.17.0) description: 'OAuth 2.1 with PKCE (S256) and dynamic client registration (RFC 7591). Live mode only; test mode is API-key only. Discovery: /.well-known/oauth-authorization-server.' see: scopes/relmcrm-com-scopes.yml sources: - openapi/relmcrm-com-openapi.yml - well-known/relmcrm-com-oauth-authorization-server.json - https://relmcrm.com/docs challenges_observed: - surface: REST request: GET https://api.relmcrm.com/v1/schema (no credential) status: 401 body: application/problem+json type https://relmcrm.com/errors/unauthorized www_authenticate: not present on the REST 401 - surface: MCP request: POST https://api.relmcrm.com/mcp tools/call relm_describe_schema (no credential) status: 401 body: >- JSON-RPC error -32001 "Authorization required. Connect with OAuth, or send Authorization: Bearer relm_live_..." www_authenticate: Bearer realm="Relm", resource_metadata="https://api.relmcrm.com/.well-known/oauth-protected-resource" note: Also mirrored in error.data._meta["mcp/www_authenticate"]; this is the RFC 9728 §5.1 hop that lets an MCP client offer a Connect button. - surface: A2A request: POST https://api.relmcrm.com/a2a message/send (no credential) status: 200 body: >- terminal Task state failed; agent message text "Authentication required. Send Authorization: Bearer relm_live_... (or relm_test_...)"; data part code unauthorized, auth bearer mcp_security_schemes_per_tool: >- every one of the 41 tools declares securitySchemes oauth2 with scopes [crm] (mcp/relmcrm-com-mcp-tools-list.json); the bearer alternative is documented in /.well-known/mcp.json. agent_card_security: >- securitySchemes oauth2 (authorizationCode, scope crm) + bearer (http); security requires oauth2 [crm] OR bearer.