Sign users in
Request a client
Email dev@nocfo.io to get an IDP client for signing NoCFO users in.
An IDP client is how your application starts a NoCFO login. It is not a personal access token, and it is not the MCP server. You use it when your product signs a person in and then calls the API as that person.
NoCFO creates the client. Send the request to dev@nocfo.io. Testing and production are separate registrations. The reply includes the client id for each environment you asked for. Your library should read its login settings from https://login-tst.nocfo.io/.well-known/openid-configuration or https://login.nocfo.io/.well-known/openid-configuration, matching that client id. Take the login and token addresses from that page.
MCP clients such as Claude and ChatGPT register themselves during connect. Do not email this address for those. Use AI connection.
What NoCFO needs
| Field | What to send |
|---|---|
| Product name | The name users should see on the consent screen. |
| Contact | An email where the client id can be sent. |
| Environment | Testing, production, or both. |
| Client type | public when the app cannot keep a secret (mobile, single-page app, PKCE). confidential when a server can hold a client secret. |
| Redirect URIs | The exact callback URLs, one list per environment. No fragments. HTTPS, or HTTP only for loopback during local development. |
| Scopes | openid profile email offline_access. offline_access is what issues a refresh token. |
| Grant types | authorization_code and refresh_token. |
| CORS origins | Only if a browser or a native app calls the token endpoint from that origin. |
| What the integration does | Which businesses and which writes it needs, so the client is not opened wider than that. |
A public client uses PKCE (S256) and has no client secret. A confidential client keeps the secret on a server. Do not put a client secret in a mobile app or a public web bundle.
Send the request
Email dev@nocfo.io with this template.
The mail body:
Product name:
Contact email:
Environment: testing / production / both
Client type: public (PKCE, no secret) / confidential
Redirect URIs (exact, per environment):
Scopes: openid profile email offline_access
Grant types: authorization_code refresh_token
CORS origins (if a browser or native app):
What the integration does:After the client exists, follow Sign users in.