> ## Documentation Index
> Fetch the complete documentation index at: https://muveya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect a client

> Connect an OAuth-capable MCP client to Muveya through Console sign-in and authorization.

Use `https://api.muveya.com/mcp` as the Streamable HTTP server URL in an MCP client that supports OAuth authorization. You do not need an API key for MCP. API keys continue to authenticate the separate `/v1` API.

## Connect

1. Add the server URL to your MCP client and choose its OAuth sign-in option.
2. The client discovers Muveya's authorization server and opens a browser. If you are signed out, Muveya Console asks you to sign in first.
3. Choose the dental clinic whose data you want the client to access. Review the application's name and requested permissions on **Authorize an MCP connection**.
4. Select **Authorize** to grant the displayed access, or **Deny** to cancel. The browser returns to the MCP client. The client then sends its access token automatically.

The connection can only use the permissions granted to both the application and your current clinic membership. Removing your membership or revoking the application's access stops subsequent calls. Each connection is limited to one dental clinic.

## Available permissions

| OAuth scope | Allows |
| - | - |
| `inventory:read` | List locations and check stock availability. |
| `catalog:read` | Search the catalog. |
| `catalog.cost:read` | Include catalog and order line costs, if your membership also allows them. |
| `orders:read` | Read orders by ID. |
| `analytics:read` | Read consumption and management figures. |

`clinics:read` and `fulfillment:read` are also supported scopes, although no current MCP tool requires them. The three person-specific tools that require `approvals.decide` or `fulfillment.pick` remain unavailable over this read-only OAuth connection. See [MCP tools](/docs/en/mcp/tools).

## If connection fails

| What you see | What to do |
| - | - |
| Sign-in page | Sign in, then choose a dental clinic to continue. |
| Invalid authorization request | Start the connection again from the MCP client. |
| Permission unavailable | Ask your clinic administrator to review your membership. Authorization cannot grant a permission you do not hold. |
| `401` from `/mcp` | Reconnect through OAuth. An API key or a token for another server will not work. |
| Tool returns `common.forbidden` | Review the permission requested by that tool and reconnect with an allowed scope. |

For a custom client, follow OAuth 2.1 authorization code with PKCE and Muveya's protected resource metadata. The client obtains and stores the access token. Do not paste a token into a chat or a shared configuration file.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.