How does the OAuth flow work?
- Your AI client requests access — it opens a Moneda authorization page in your browser
- You sign in and approve — with your passkey, Google, or Apple, then review the permissions the AI is requesting and approve or deny
- A secure token is issued — the AI client receives a token to access your account data. Your password is never shared.
- Tokens refresh automatically — the connection stays active without you needing to re-authorize
What permissions does my AI assistant need?
When you authorize, you’ll see a consent screen listing the specific permissions your AI needs. These are grouped into read and write scopes:- Read scopes let your AI view data (balances, transactions, contacts, etc.)
- Write scopes let your AI take actions (update your display name, categorize transactions, initiate payments)
How do I revoke access?
Ask your assistant to list your connected agents and disconnect the one you no longer want (list_active_sessions, then disconnect_connected_service). A disconnected connection is refused on its very next request — by the MCP server and by the REST API alike, so a client can’t fall back to one after losing the other.
Learn more
Scopes reference
Full list of 24 read and 12 write permission scopes.
Security
How Moneda protects your funds and data.
