Authentication & registration
Guide

Authentication & registration

JetHost MCP uses OAuth 2.1 with Dynamic Client Registration (RFC 7591) and PKCE. AI clients register themselves and obtain a scoped token after you approve a consent screen inside your JetHost account.

OAuth 2.1PKCE requiredDynamic Client Registration
This page describes the default connection flow. Accounts with the opt-in Advanced Token Manager enabled refuse generic clients — registration and consent return a Advanced Token Manager enabled error — and connect through owner-created credentials instead.

Endpoints #

Clients auto-configure from the two discovery documents — no manual setup. The protected-resource document points to the authorization server, which advertises the rest. The OAuth discovery documents are also served with an /mcp path suffix (e.g. /.well-known/oauth-authorization-server/mcp) for clients that append the resource path.

PurposeURL
Discovery — protected resourceGET https://mcp.jethost.bg/.well-known/oauth-protected-resource
Discovery — authorization serverGET https://mcp.jethost.bg/.well-known/oauth-authorization-server
Registration (DCR)POST https://jethost.bg/app/index.php?m=jethost_mcp_oauth&action=register
MCP transportPOST https://mcp.jethost.bg/mcp
AuthorizationGET https://jethost.bg/app/index.php?m=jethost_mcp_oauth&action=authorize
TokenPOST https://jethost.bg/app/index.php?m=jethost_mcp_oauth&action=token
JWKSGET https://jethost.bg/app/index.php?m=jethost_mcp_oauth&action=jwks
Token revocationPOST https://jethost.bg/app/index.php?m=jethost_mcp_oauth&action=revoke
Manage tokensGET https://jethost.bg/app/index.php?m=jethost_mcp_oauth&action=manage_tokens
Discovery — OIDC aliasGET https://mcp.jethost.bg/.well-known/openid-configuration
MCP server cardGET https://mcp.jethost.bg/mcp/server-card
MCP server card — well-known aliasGET https://mcp.jethost.bg/.well-known/mcp/server-card.json
AI catalogGET https://mcp.jethost.bg/.well-known/ai-catalog.json
API catalog (RFC 9727)GET https://mcp.jethost.bg/.well-known/api-catalog
Agent skills indexGET https://mcp.jethost.bg/.well-known/agent-skills/index.json
Agent registration recipeGET https://mcp.jethost.bg/auth.md

Server metadata #

Advertised by /.well-known/oauth-authorization-server (RFC 8414):

issuerhttps://jethost.bg/app
scopes_supported12 scopes (see below)
response_types_supportedcode
grant_types_supportedauthorization_code, refresh_token
code_challenge_methods_supportedS256 — PKCE required
token_endpoint_auth_methods_supportednone — public clients
registrationopen · RFC 7591 Dynamic Client Registration

How connecting works #

  • The client fetches the discovery documents (/.well-known/oauth-protected-resource → /.well-known/oauth-authorization-server), then registers itself at the Registration endpoint via Dynamic Client Registration — no manual client_id setup.
  • It opens the Authorization URL; you sign in to JetHost (reusing your existing session and 2FA) and approve the requested scopes on a consent screen.
  • The client exchanges the authorization code (with its PKCE verifier) at the Token endpoint for a short-lived access token (15 min) and a rolling refresh token (30 days; refresh tokens minted by a Advanced Token Manager credential are instead capped at the credential's expiry).
  • Every MCP call sends Authorization: Bearer <access_token>. The server verifies the token and enforces scope + ownership on each tool (see Token types).
  • You can review and revoke tokens anytime from Manage tokens.

Token types #

  • OAuth access tokens (this flow) are RS256 JWTs: the server verifies the signature offline against the JWKS, then checks the grant live so revocation applies immediately.
  • API paste tokens (jh_pat_…, 50 characters) exist only for Advanced Token Manager credentials. They are opaque — nothing to verify offline — so the server introspects each one against the authorization server on every request and fails closed: if the check cannot complete, the call is denied.

The catalog tools (list_hosting_plans, get_hosting_plan, check_domain_availability, suggest_domains) return public catalog data with either token type — the token never filters which entries return; it only personalizes prices to your account, such as partner pricing.

Scopes #

Each tool requires one scope. A client requests only the scopes it needs; you approve them on the consent screen.

ScopeGrants
cpanel:uapiManage your hosting account via cPanel — read and change settings on the cPanel features JetHost has enabled (this can modify your account)
generate_deploy_key list_cpanel_operations get_cpanel_module cpanel_uapi list_wordpress_operations get_wordpress_module wordpress_manage
read:analyticsRead your websites' traffic statistics and visitor analytics
get_website_statistics
read:deployView the deployment status and history of your websites
get_deploy_status get_private_repo_deploy_status
read:domain_catalogCheck domain availability and get EUR pricing from JetHost's catalog
check_domain_availability suggest_domains
read:domainsView your registered domains and their details
list_domains get_domain get_domain_nameservers get_domain_whois
read:invoicesView your invoices and billing history
list_invoices get_invoice search_invoices find_invoices_by_relation
read:logsRead your websites' access logs and PHP error logs
get_website_logs
read:product_catalogView JetHost's hosting plans with EUR pricing
list_hosting_plans get_hosting_plan
read:servicesView your hosting services
list_services get_service get_service_usage
read:ticketsView your support tickets and conversation history
list_tickets get_ticket
read:websitesView the domains and document roots hosted on your hosting accounts
list_website_domains
write:deployDeploy websites from a git repository — a public URL or a private SSH repo — to your hosting (overwrites the target site)
deploy_site_from_url deploy_private_repo