OAuth & consent
Consent UI: https://bruce.money/developers/mcp/authorize (Privy login).
- Select organization
- Select scopes (allowlisted)
- Issue short-lived
bat_token (default 8 hours)
Server: POST /api/oauth/mcp-token (session JWT). MCP Worker /authorize redirects here.