Kosmodrom MCP OAuth 2.1 Add this server URL to your AI app as an MCP connector; the app opens Kosmodrom sign-in and asks you to allow access. Scopes: read (always), write (optional). A refresh token is always issued; offline_access is accepted. Client registration: dynamic (RFC 7591) or Client ID Metadata Document (client_id is an https URL). Platforms without dynamic registration (Gemini Enterprise): a Kosmodrom admin issues a Client ID and Client Secret in the profile, AI agents tab; client_secret_post and client_secret_basic are accepted. Access tokens live 1 hour, refresh tokens rotate on every use. Revoke via /oauth/revoke or in Kosmodrom profile.