Keys, sign-in and permissions

How to authenticate to the connector with a key or with OAuth, which permissions exist, and how long each credential lasts.

GuideDeveloperChecked 2026-10-10

You can authenticate to the connector two ways: a key you create in the app, or OAuth sign-in. Both send Authorization: Bearer <credential>. A key works on the connector only.

The three credentials

Credential Looks like Made by Lifetime Used for
Key adl_ plus 40 hex characters You, in the app 365 days by default, 730 at most The connector, in any client that accepts a header
OAuth access token ado_... The sign-in flow 1 hour The connector, for Claude and ChatGPT
Sign-in token A long signed token POST /market/auth/login 30 days The app's own routes. See How the app's API is organised

A key is not a sign-in token. Sending a key to a route outside the connector gets 401 Could not validate credentials.

Create a key

  1. Open the Stack page (#/stack).
  2. In Your tools, on the MCP connector line, press Keys and details.
  3. Type a name in the box at the bottom, for example "Claude on my laptop".
  4. Press Create a key.
  5. Copy the key from the box that appears. It is shown once and cannot be recovered. Only a one-way hash is stored.

Up to 10 keys can be active on an account. To stop a key, press Revoke twice on its line. It stops working at once and the next call gets a 401.

A key made this way carries the default permissions: book:search, book:read and account:read. The window has no way to choose others.

POST https://app.adaptleads.co.uk/api/market/tokens
Authorization: Bearer <sign-in token>
Content-Type: application/json

{"label": "Reports bot", "scopes": ["book:search", "lists:read"], "ttl_days": 90}

The reply holds the key once, with "shown_once": true, plus prefix, scopes and expires_at. Unknown permission names are dropped, so a typo narrows a key and never widens it. An empty list makes a key that can do nothing. A key cannot create another key.

Permissions

There are 20 permissions and no "all access" one. The full list with what each allows is in Permissions and limits. A tool that needs a permission the key lacks returns forbidden and does not use any of your call allowance.

Accounts that Adapt has marked as super admin get every permission on their keys.

OAuth for Claude and ChatGPT

Claude and ChatGPT do not need a key. They discover the sign-in themselves.

Step Address
Protected resource metadata https://app.adaptleads.co.uk/.well-known/oauth-protected-resource
Authorisation server metadata https://app.adaptleads.co.uk/.well-known/oauth-authorization-server
Register a client POST https://app.adaptleads.co.uk/api/market/oauth/register
Authorise GET https://app.adaptleads.co.uk/api/market/oauth/authorize
Token POST https://app.adaptleads.co.uk/api/market/oauth/token
  • Only public clients are accepted (token_endpoint_auth_method of none), and PKCE with S256 is required.
  • Redirect addresses must be https, or http on 127.0.0.1, localhost or ::1. A loopback redirect matches on any port.
  • Two scopes exist: adapt:read (read your book, lists, campaigns and connections) and adapt (adds the ability to prepare changes). Neither can start a campaign or send.
  • The resource is https://mcp.adaptleads.co.uk/. A request for any other resource is refused.
  • An authorisation code lasts 5 minutes. An access token lasts 1 hour. A refresh token lasts 30 days and works once: using it returns a new pair, and using the old one again is refused.
  • The person signs in on an Adapt page with their email and password, or Google, and the connection is tied to their account and organisation.

OAuth errors come back as {"error": "invalid_grant", "error_description": "..."}. See Errors and what they mean.

Who can sign in

Sign-in may be limited to an approved list of addresses. If yours is not on it you get 403 with "AdaptLeads is not open for public sign-up yet." Closed and suspended accounts lose every credential at once, including keys and OAuth tokens that have not expired.