Most AI clients need one thing: the server URL https://freddy.coach/mcp. Paste it in and the client works out the sign-in by itself. The rest of this page is for clients that ask for more.
For a specific client, see Connect freddy to Claude, Connect freddy from ChatGPT, or Connect freddy from Claude Code. If something does not work, see agent troubleshooting.
1. Standard OAuth, which most clients use
freddy speaks OAuth 2.1 with PKCE and dynamic client registration. Claude, ChatGPT, Cursor, Muse and most connector platforms handle all of it themselves once they have the server URL, so you sign in with a normal browser approval and nothing to copy.
If a setup screen asks you to fill the details in by hand:
- Server URL: https://freddy.coach/mcp
- Authorization URL: https://freddy.coach/oauth/authorize
- Token URL: https://freddy.coach/oauth/token
- Registration URL: https://freddy.coach/oauth/register
- PKCE: required, S256
- Scopes: mcp account:read connections:write
If the screen asks for a client ID and a client secret, register one yourself. Use the exact redirect URL that the setup screen shows you, in place of the example below.
curl -sX POST https://freddy.coach/oauth/register \
-H "Content-Type: application/json" \
-d '{"client_name":"My client","redirect_uris":["https://example.com/callback"]}'The response carries client_id and client_secret. Registration is open, so you do not need anything from us first.
2. Device flow, for agents with no browser
If your agent runs in a terminal or on a server and cannot open a redirect, freddy also supports device flow (RFC 8628). The easiest path is the freddy CLI: npx @freddy-coach/cli login walks the whole flow for you, including connecting data sources and refreshing tokens. See Use the freddy CLI.
If your agent cannot run the CLI, run this once in a terminal and paste the access token wherever your agent expects an MCP bearer token. The token is good for 1 hour, and the recipe also returns a 60-day refresh token for renewal.
APP=https://freddy.coach
CLIENT=$(curl -sX POST $APP/oauth/register \
-H "Content-Type: application/json" \
-d '{"client_name":"My Agent","redirect_uris":["http://localhost"]}' \
| jq -r .client_id)
DA=$(curl -sX POST $APP/oauth/device_authorization \
--data-urlencode "client_id=$CLIENT" \
--data-urlencode "scope=mcp account:read connections:write")
DEVICE=$(echo "$DA" | jq -r .device_code)
URL=$(echo "$DA" | jq -r .verification_uri_complete)
echo "Open: $URL"
while :; do
R=$(curl -sX POST $APP/oauth/token \
--data-urlencode "grant_type=urn:ietf:params:oauth:grant-type:device_code" \
--data-urlencode "client_id=$CLIENT" \
--data-urlencode "device_code=$DEVICE")
ERR=$(echo "$R" | jq -r .error)
case "$ERR" in
authorization_pending|slow_down) sleep 6 ;;
null) echo "$R" | jq -r .access_token; break ;;
*) echo "stop: $ERR"; break ;;
esac
doneThe recipe prints a sign-in URL. Open it in a browser, approve, and the script prints the access token.
3. Permanent MCP URL, as a last resort
Some clients speak MCP but cannot refresh the one-hour access token. The symptom is that everything works for about an hour, then every tool stops responding, often shown as an "unknown tool" error, and the client cannot recover on its own.
For those clients, use your permanent MCP URL instead. It looks like https://freddy.coach/mcp/<token>, it never expires, and it takes no Authorization header. Get it in any of these ways:
- Copy it from the MCP URL card on your freddy dashboard.
- Run npx @freddy-coach/cli url.
- Run npx @freddy-coach/cli profile --json and read the mcpUrl field.
Treat that URL like a password. It carries full access to your account and it cannot be narrowed, so prefer OAuth wherever the client supports it. If it ever leaks, rotate it from your dashboard and the old URL stops working immediately.
What the client can do once signed in
freddy exposes seven tools:
- get_profile, list_metrics and query_metrics read your data.
- connect_source, sync_source and disconnect_source manage your connected sources.
- accept_terms records your agreement when a policy is updated.
A signed-in client can also read your audit log and manage your account settings over freddy's REST surface, using the scopes you approved.
Privacy and revocation
Each sign-in produces a grant tied to your freddy account. You can review and revoke connected clients from your dashboard under Connected AI. Revoking a grant invalidates that client's tokens immediately.
Need help?
Email [email protected], or message us in the app.