Stytch · Capability
Stytch Connected Apps & MCP Authorization
Treat your Stytch-secured product as an OAuth 2.0 / OIDC Authorization Server so external clients — desktop apps, AI agents, MCP servers, and third-party integrations — can request scoped, user-consented access to it. This capability composes the Connected Apps client lifecycle (create, search, update, delete clients), the OAuth Authorization endpoint flow, token issuance, IDP introspection, and the Consumer / B2B session checks that gate user consent.