Get started

Authentication

What needs no account, how an agent signs in with OAuth, and what a token can do.

What needs nothing

  • https://mora.market/mcp/public: the read-only MCP endpoint.
  • Every GET of the REST API.
  • The free dataset search.

Signing in

https://mora.market/mcp and every POST use OAuth 2. You do not create a key: the client registers itself and the person signs in once in the browser, with Google or an emailed code.

A call without a token is answered with 401 and a pointer to the sign-in server. That answer is what makes an MCP client open the browser.

http
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer resource_metadata="https://mora.market/.well-known/oauth-protected-resource"
bash
curl https://mora.market/.well-known/oauth-protected-resource
json
{
  "resource": "https://mora.market/mcp",
  "authorization_servers": ["https://<sign-in server>"],
  "bearer_methods_supported": ["header"],
  "scopes_supported": ["profile", "email"]
}

Send the access token on every call:

http
Authorization: Bearer <access token>

What a token can do

A token acts for one account, and an account belongs to one company with one profile.

Profile Can Cannot
Provider Connect tools, create listings, send records, read open requests, follow deals Make offers
Lab Ask for data, prepare offers, follow deals Create listings

Tools that do not fit the profile are not offered to the agent at all.

What is not there yet

  • API keys. A script uses the OAuth access token of the account it acts for.
  • Several people per company. One account is one company today.

Being verified

Nothing asks who you are to list, to search, to test a sample or to make an offer.

Mora verifies both sides when a deal is agreed, before money moves: an identity document for a person, the company for a lab. The data of a licensed dataset opens once the offer was accepted and both sides are verified.