Skip to content
  • Everything in KeplarEvery feature and whether it is liveLive demoAsk a question now, no sign-upCreateDescribe or speak a site or appCreate showcaseDemos that set the barKeplar-OneThe engine behind every answerTeamsShared workspaces, roles and approvals
  • DocsHow everything worksAPI and widgetKeys, endpoints, embed scriptCommunity gallerySites people chose to shareChangelogWhat shipped, whenRoadmapWhat is next, what is not doneSecurityHow your data is protected
  • Pricing
  • Download
Sign InTry Keplar→
  • Product
  • Live demo
  • Create
  • Create showcase
  • Keplar-One
  • Teams
  • Resources
  • API and widget
  • Community gallery
  • Changelog
  • Roadmap
  • Security
  • Pricing
  • Download
Sign InTry Keplar→

One question. Multiple intelligences. One answer.

team@keplar.one

Product

  • Everything in Keplar
  • Overview
  • Live demo
  • How it works
  • Create
  • Create showcase
  • Community gallery
  • Keplar-One
  • Pricing
  • Download

Use Keplar

  • For you
  • For business
  • Agents
  • API and widget
  • Referral program
  • Create an account

Learn

  • AI answer engine
  • Compare AI models
  • AI study tool
  • AI slideshow maker
  • What is superintelligence?
  • Multi-model AI
  • Models we use
  • Guides
  • Docs
  • Blog
  • Changelog
  • Roadmap
  • Glossary
  • Prompt library

Company

  • About
  • Inquire
  • Help
  • Contact
  • Status

Legal

  • Privacy
  • Terms
  • Security

© 2026 Keplar One.

Theme
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do
Docs menu
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do

Docs/Connectors and agents

Connect with OAuth (Beta)

How OAuth sign-in for remote MCP servers works in Keplar, what it stores, what it refuses, and why it is labeled Beta.

Updated October 3, 20261 min read

On this page
  1. What happens
  2. What it refuses
  3. Why Beta
  4. State protection
  5. Limits of the current version

Some remote servers only accept sign-in with an account on that service. Choose OAuth (BETA) in Add a connection, approve on the provider's own page, and Keplar keeps only encrypted tokens.

What happens

  1. Keplar probes the server and reads its sign-in challenge, then discovers the authorization server's metadata using the standard documents (RFC 9728 protected-resource metadata, RFC 8414 or OpenID Connect discovery).
  2. It registers itself as a public client dynamically (RFC 7591) and starts a sign-in using PKCE with the S256 method and the resource parameter (RFC 8707).
  3. You approve on the provider's page. Keplar's callback needs your signed-in session and reflects nothing from the query string.
  4. Keplar stores the access and refresh tokens sealed with encryption bound to your workspace and the connection. They are never returned by any API.
  5. Tokens refresh about a minute before they expire. A rejected token triggers one forced refresh; a definite invalid-grant marks the connection "sign in again".

What it refuses

Servers whose metadata does not match, that do not offer PKCE S256 and dynamic registration, or whose endpoints are not public HTTPS. Services that require a pre-registered app are refused with a clear reason. Scopes are requested only if the server's challenge named them; there is no automatic escalation.

Why Beta

OAuth was tested end to end against a fake authorization server, and the real discovery documents of Linear, Notion and Sentry were fetched and parsed on 2 October 2026. A sign-in with a real provider account has not been completed, so the feature is labeled Beta. Expect rough edges and report them.

State protection

The sign-in state is random, bound to your workspace and connection, single-use, expires after 10 minutes, and is stored sealed with the PKCE verifier. A mismatched issuer or a denial is refused.

Limits of the current version

No pre-registered client ids or secrets, no scope step-up, and the older SSE transport is unsupported.

Related

  • Add a connection: Connect an MCP server step by step, test it with a handshake, enable only the tools you want, and the address and credential rules that apply.
  • Connected app security: How Keplar defends against server-side request forgery, prompt injection through tool output, secret leaks and silent tool changes when you connect MCP servers.
  • Tool permissions and approvals: Read versus write tools, grants, auto-run rules, approval cards, schema-change locks and how scheduled runs always ask first.
PreviousAdd a connectionNextTool permissions and approvals

Questions this page does not answer? Write to team@keplar.one, or try Keplar on your own question.

Try Keplar freeOpen Keplar→

On this page

  1. What happens
  2. What it refuses
  3. Why Beta
  4. State protection
  5. Limits of the current version