intelux.ai
← back to How OAuth Works
Chapter 06 · Bonus · Security

The Badge to the Top Floor

🤖Claudeyour assistant · OAuth client
🧑‍💼Yousent Claude · not in the OAuth flow
💂Door guardMCP server · /mcp
🛎️Receptionauthorization server
👔the CEOresource owner · approves
HQ · animated
YOU · sent Claude 🧑‍💼 💬 “get me his view” not part of the OAuth flow HQ TOP FLOOR · CEO SUITE 💂 /mcp main door 401 ✋ CEO SUITE → reception lobby sign discovery 💁 RECEPTION 📖 🛎️ reception authorization server 🗑️ intercom consent turnstile Bearer check elevator 👔 🪴 CEO ☎️ 📁 APPROVED REVOKED 🤖 ✉️ 🧾 🎫 🪪 🎟️ 📝

What really happens

🔐 What really happened

The person who approved was the resource owner: the one whose views were behind the door. Not Claude, and not you. Claude never learned the owner’s PIN. It walked out with a visitor badge (access token) that opens one floor (scope), in one building (resource), for one hour, plus a renewal voucher (refresh token) that is torn up every time it’s used. Every swipe is logged, and the owner can cancel the badge with one call.

The claim ticket (authorization code) was useless to anyone who picked it up, because only Claude knew the secret phrase sealed in the envelope (PKCE). The reference number (state) proved the ticket answered Claude’s own request, and the return address (redirect_uri) was written in the visitor book, so the ticket could only go to Claude.

Keep in your pocket: door says 401 → read the sign → sign the book → seal the envelope → ask the desk → the owner approves on the intercom → claim ticket → ticket + secret phrase = badge → swipe on every call → renew hourly → the owner can revoke.

Who plays which role

same five roles, three stories
OAuth roleIn the buildingGoogle: an app reading GmailProxima + Claude
Resource owner👔 the CEO: his views are his to shareYou, the Gmail account holderYou: it’s your household data
ResourceHis notes on the prospectYour emailsYour bills, solar, water…
Resource server💂 The CEO suite behind the guarded doorGmail’s APIProxima /mcp
Authorization server🛎️ Reception (same company, same building)Google’s sign-in serviceProxima /authorize + /token
Client🤖 Claude, the visiting assistantThe third-party appClaude
Not in the flow🧑‍💼 You, who sent Claude(nobody)(nobody: you’re the owner here)

The golden rule: the intercom always rings the resource owner. In Proxima the owner and the person asking are the same (you), which is why you approve there.

The building, decoded

analogy → OAuth 2.1 / MCP
In the buildingReal nameWhy it exists
💂 Door guardPOST /mcp → 401No badge, no entry. The 401 also says where reception is (resource_metadata).
🪧 Lobby signProtected resource metadataTells any visitor which reception issues badges for this suite. Only the address is needed to start.
📋 Window listAuthorization server metadataWhere to register, where to ask, where badges are issued, and that envelopes must be SHA-256 sealed.
📖 Visitor bookDynamic client registration → client_idThe desk has never met Claude. The return address written here is the only place tickets may go.
✉️ Sealed envelopePKCE: code_challenge / code_verifierProves the person redeeming the ticket is the one who asked. A stolen ticket is worthless.
🔢 Reference numberstateStops someone slipping their ticket into Claude’s hands (CSRF).
🏠 Return addressredirect_uri (exact match)Tickets can’t be mailed to a look-alike address.
🧾 Request slipGET /authorizeWho, which floor (scope), which building (resource), reference number, envelope.
📞 Intercom + PINConsent page + the owner’s passwordOnly the resource owner can approve, and the PIN never reaches Claude.
🎫 Claim ticketAuthorization codeSingle use, 5 minutes. Travels through the front channel, so it opens nothing on its own.
🪪 Visitor badgeAccess token (Bearer, 1 hour)Opens one floor of one building for an hour. Shown on every request.
🎟️ Renewal voucherRefresh token (rotates)New badge every hour without calling you again. A copied voucher works once at most.
🚦 Turnstile + logToken validation + audit logChecks expiry, floor and building on every swipe, and writes it down.
👔 The meetingtools/callThe actual MCP request: the question goes in, the CEO’s notes come back as the result.

Up next in the series
How WebSockets Work →