Who it’s for
- ChatGPT users. ChatGPT (apps and connectors, in developer mode) connects to Bland by signing in today.
- Client developers whose client identifies itself with a client ID metadata document. See For client developers.
What you see when you connect
Add the Bland server in your client
https://api.bland.ai/v1/mcp. The client discovers Bland’s authorization server on its own and opens Bland in your browser.Sign in
v2.app.bland.ai with your phone number, Google, or SSO.Choose an organization
Review what the client gets
Use the tools
Scopes and consent
mcp:read, Write and Destructive tools need mcp:write. The tool reference shows each tool’s access level.
Step-up consent
If a tool needs a scope the connection wasn’t granted, for example a write tool on a read-only connection, the server answers403 with a WWW-Authenticate challenge that lists the required scopes. Your client then asks you to grant them. The consent screen pre-checks what you already granted, so you approve only the addition.
Tokens and disconnecting
- Access tokens are JWTs. Each one lasts 1 hour and is scoped to one organization.
- If you granted Stay connected without signing in again, the client holds a refresh token and renews its access on its own.
- To disconnect, remove or disconnect the Bland app in your client. The client revokes its tokens at
https://api.bland.ai/authorization/oauth2/revoke. - A connected-apps page in the dashboard, for reviewing and revoking connections, is planned.
buy_credits, buy_phone_plan) aren’t offered. Buy credits and phone plans in the dashboard, or over an API key connection. Every other tool behaves as it does with an API key, scoped to the organization you chose and the permissions of your role in it.
Client support
For client developers
Bland’s authorization server implements OAuth 2.1 authorization code with PKCE, and the MCP server publishes the discovery documents an MCP client expects.https://api.bland.ai/authorization as the authorization server and mcp:read and mcp:write as the supported scopes. Bearer tokens are accepted in the Authorization header only.
- Use PKCE with
S256. It’s required on every authorization request. - Identify itself with a client ID metadata document. Your
client_idis an HTTPS URL that serves your client’s metadata JSON. The server metadata advertises this withclient_id_metadata_document_supported: true. Dynamic client registration (RFC 7591) isn’t available yet. - Send
resource=https://api.bland.ai/v1/mcp(RFC 8707) in authorization and token requests. The token is only valid on/v1/mcp, not on the REST API. - Request the scopes it needs.
mcp:readfor read tools,mcp:writefor write tools, plusopenid,email, andoffline_accessas needed.
- No credential:
401withWWW-Authenticate: Bearer realm="bland", resource_metadata="https://api.bland.ai/.well-known/oauth-protected-resource/v1/mcp", scope="mcp:read mcp:write". Followresource_metadatato start discovery. - Missing scope:
403with aWWW-Authenticatechallenge that lists the required scopes. Re-run authorization requesting them; the consent screen pre-checks what the user already granted. - Scopes per tool:
tools/listreturns each tool’s required scopes insecuritySchemes, withreadOnlyHint,destructiveHint,idempotentHint, andopenWorldHintannotations, so you can request the right scopes up front.
FAQ
Can I give a client read-only access?
Can I give a client read-only access?
mcp:read only. If it later calls a write tool, it asks you to grant mcp:write.Can I buy credits or a phone plan over a sign-in connection?
Can I buy credits or a phone plan over a sign-in connection?
buy_credits and buy_phone_plan aren’t offered over OAuth. Buy in the dashboard, or over an API key connection.Does the token work on the REST API?
Does the token work on the REST API?
/v1/mcp. Use an API key for the REST API.Which organization does the client act in?
Which organization does the client act in?
My client already uses an API key. Do I need to change anything?
My client already uses an API key. Do I need to change anything?
Authorization: Bearer org_... never sees the sign-in flow.Can I review which apps are connected?
Can I review which apps are connected?