# Authentication and permissions

> OAuth 2.1 with PKCE, per-group permission scopes and access revocation for the Sidemex MCP server.

The Sidemex MCP server is an OAuth resource server. Sign-in uses the same account system as the sidemex.net dashboard.

## Flow

1. The MCP client discovers configuration at `https://mcp.sidemex.net/.well-known/oauth-protected-resource/mcp`.
2. It opens Sidemex sign-in with **PKCE (S256)**.
3. You choose the permissions.
4. The client receives a short-lived access token valid only for the Sidemex MCP server.

## Scopes

| Scope | Allows |
|---|---|
| `domains:read` | View your domains, quote, create payment links, check orders |
| `dns:write` | Create, change and delete DNS records on your domains |
| `email:write` | View, create and delete mailboxes; generate password-change links |
| `balance:read` | View balance and history |

An assistant can only do what the approved scopes allow, and only on domains in your account.

## Revoking access

From your sidemex.net dashboard you can see which applications have access and revoke it at any time. Every action an assistant takes is recorded in your activity history.

---
https://docs.sidemex.app/en/conceptos/autenticacion/
