Guest: /mcp
No credential is needed to connect. Each scan is authorised by its own capability:
start_skin_scanreturns arun_idand a 64-hexaccess_token.- Every later call on that scan must send both.
- The server stores only a keyed hash of the token.
- A wrong token and a missing scan both return
not_found, so arun_idcannot be probed. delete_skin_scanrevokes the token immediately. A guest scan’s token stops working after seven days.
/scan/:id) is opened by the person, not the agent. The page runs Cloudflare Turnstile, records consent, and sets a __Host- cookie. The upload is accepted only from the browser that consented, so an agent holding the link cannot swap the photo.
Account: /mcp/account
OAuth 2.1 with PKCE (S256 only), dynamic client registration and refresh tokens. Without a valid bearer token the endpoint returns 401.
Scopes
At
/authorize the person signs in with Google or Apple through Skan’s Firebase project, which is the same identity the Skan app uses. Anonymous identities are refused. They then approve the listed scopes. Redirect URIs must match the registered value exactly; a mismatch or an unknown client gets a 400 page and is never redirected.
Signed-in calls carry a verified account identity. Limits apply per account instead of per network, and delete_my_skan_data becomes available.
Saving a guest result
A completed guest scan returns asave_url. The person opens it, signs in with Google or Apple and explicitly chooses to save; that is the only way a guest scan joins an account. No tool saves a result or creates an account.