Get started
Authentication
What needs no account, how an agent signs in with OAuth, and what a token can do.
What needs nothing
https://mora.market/mcp/public: the read-only MCP endpoint.- Every
GETof the REST API. - The free dataset search.
Signing in
https://mora.market/mcp and every POST use OAuth 2. You do not create a key: the client registers itself and the person signs in once in the browser, with Google or an emailed code.
A call without a token is answered with 401 and a pointer to the sign-in server. That answer is what makes an MCP client open the browser.
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer resource_metadata="https://mora.market/.well-known/oauth-protected-resource"curl https://mora.market/.well-known/oauth-protected-resource{
"resource": "https://mora.market/mcp",
"authorization_servers": ["https://<sign-in server>"],
"bearer_methods_supported": ["header"],
"scopes_supported": ["profile", "email"]
}Send the access token on every call:
Authorization: Bearer <access token>What a token can do
A token acts for one account, and an account belongs to one company with one profile.
| Profile | Can | Cannot |
|---|---|---|
| Provider | Connect tools, create listings, send records, read open requests, follow deals | Make offers |
| Lab | Ask for data, prepare offers, follow deals | Create listings |
Tools that do not fit the profile are not offered to the agent at all.
What is not there yet
- API keys. A script uses the OAuth access token of the account it acts for.
- Several people per company. One account is one company today.
Being verified
Nothing asks who you are to list, to search, to test a sample or to make an offer.
Mora verifies both sides when a deal is agreed, before money moves: an identity document for a person, the company for a lab. The data of a licensed dataset opens once the offer was accepted and both sides are verified.