TianGong LCA Documentation
Integration & Extension

TianGong LCA MCP (Remote)

Connect to remote TianGong LCA tools through standards-based MCP OAuth 2.1 browser authorization.

The remote endpoint is https://lcamcp.tiangong.earth/mcp. Use an MCP host that supports Streamable HTTP, OAuth 2.1, PKCE, and Protected Resource Metadata.

Browser authorization

  1. Select Streamable HTTP in the MCP host and enter the remote endpoint.
  2. The first connection receives a 401 with resource_metadata. The host reads /.well-known/oauth-protected-resource/mcp and the authorization-server metadata automatically.
  3. The host opens the browser with a preregistered public client ID and S256 PKCE. Dynamic Client Registration is disabled for the initial production release; unregistered clients or callbacks cannot connect.
  4. The user signs in at the TianGong Life Cycle Data Platform, reviews the application, account, and requested access on the consent page, and allows or denies it.
  5. The browser returns to the host's exact callback. The host exchanges the code directly with Supabase and stores the rotating refresh token in its own protected local credential store. The user never copies an authorization code or views or pastes a token.

Supabase issues a standard short-lived Supabase access JWT. The MCP resource server verifies its ES256 signature through Supabase JWKS and validates iss, aud, exp, iat, sub, session_id, role, and the exact admitted client_id. It forwards that same JWT to Edge Functions or PostgREST; Edge runs getClaims() independently, and database RLS combines auth.uid() with auth.jwt() ->> 'client_id'. The MCP service stores no OAuth session or refresh token and uses no Redis for authentication.

Never give an AI, chat window, command argument, or manual header a username, password, authorization code, access token, or refresh token. The remote service supports only Authorization Code + S256 PKCE and refresh, with neither password nor client-credentials grants.

Claude Code

Use the public client ID and fixed callback pair registered by the operator for Claude Code:

claude mcp add --transport http --scope user \
  --client-id "<registered-claude-code-client-id>" \
  --callback-port 49192 \
  tiangong-lca https://lcamcp.tiangong.earth/mcp

Open Claude Code, select tiangong-lca from /mcp, and authenticate in the browser. Claude Code keeps the refresh token locally; do not add an Authorization header or client secret.

Codex

Before login, put the public client ID, global loopback callback base, and fixed listener port in ~/.codex/config.toml:

mcp_oauth_callback_url = "http://127.0.0.1:49193/callback"
mcp_oauth_callback_port = 49193

[mcp_servers.tiangong_lca]
url = "https://lcamcp.tiangong.earth/mcp"
oauth_resource = "https://lcamcp.tiangong.earth/mcp"

[mcp_servers.tiangong_lca.oauth]
client_id = "<registered-codex-client-id>"
codex mcp login tiangong_lca --scopes openid,email,profile

Codex combines this base with the stable callback ID for the MCP URL, producing http://127.0.0.1:49193/callback/sB-dwg9ebTQE, the final redirect URI registered byte-for-byte in Supabase. An explicit URL port does not configure the listener, so mcp_oauth_callback_port must also remain 49193. Codex opens the browser and keeps the rotating refresh token in its local credential store. Do not enable DCR, add a client secret, or paste a bearer token.

MCP Inspector

npx @modelcontextprotocol/inspector
  1. Select Streamable HTTP.
  2. Enter https://lcamcp.tiangong.earth/mcp as the URL.
  3. Use the preregistered client ID supplied by the operator. Do not generate a client or paste a Bearer token.
  4. Connect and complete authorization in the browser that opens.
  5. Open Tools → List Tools and run a search or another tool.

The initial fixed-client rollout supports only registered hosts. If Cherry Studio, Dify, or another host supports only manual Authorization headers or requires Dynamic Client Registration, it is not yet a supported path; do not work around this by copying tokens.

Session, refresh, and revocation

  • Access tokens are short-lived; the host renews them with a rotating refresh token.
  • Disconnecting or signing out locally should remove the host's client-local OAuth credentials, but it does not replace account-side revocation.
  • Revoking the corresponding Claude Code, Codex, or Inspector client under Connected applications immediately invalidates its Supabase sessions and refresh tokens. An already issued short-lived access JWT can remain cryptographically valid until expiry when services use local JWKS validation; sensitive operations follow their own online-validation contract.
  • After revocation, refresh replay, a client/callback mismatch, or an invalid grant, reconnect and authorize again in the browser.

Headless and service identities

Supabase OAuth supports Authorization Code + PKCE and refresh only. An unattended workflow must first receive human authorization for a fixed client and store its refresh session in an approved secret store, or receive a short-lived actor token from its orchestrator. Never let an AI collect account credentials. A truly userless integration uses a separately reviewed service capability instead of pretending to be user OAuth.

Tool and data boundary

The tool list normally includes Flow, Process, and LifecycleModel search plus RLS-protected data operations. If GLAD is enabled, it also includes Search_GLAD_Datasets_Tool and Get_GLAD_Dataset_Tool; the GLAD API key exists only on the remote server. GLAD tools query external dataset metadata and never import data automatically.

On this page