Jepto
Help Center
Close


Data Sources

General

Data Sources | General

Connections

Data Sources | Connections

Fields & Formulas

Data Sources | Fields & Formulas

Reports

Creating & Sharing

Reports | Creating & Sharing

Report Editing

Reports | Editing

Report Config

Reports | Report Config

Chart Cards

Reports | Chart Cards

Content Cards

Reports | Content Cards

Data Chat

General

Data Chat | General

AI

General

AI | General

Clients

General

Clients | General

Integrations

General

Integrations | General

MCP

Integrations | MCP

Webhook — Local & Reviews

Integrations | Webhook — Local & Reviews

Webhook — Automation Payloads

Integrations | Webhook — Automation Payloads

Webhook — Other

Integrations | Webhook — Other

Settings

Account & Billing

Settings | Account & Billing

Users

Settings | Users

Comments & Notes

Settings | Comments & Notes

Notifications

Settings | Notifications

FAQ

Settings | FAQ

Other

Settings | Other

KPI Forecasting

General

KPI Forecasting | General

Settings & Status

KPI Forecasting | Settings & Status

Seasonality

KPI Forecasting | Seasonality

Metrics by Source

KPI Forecasting | Metrics by Source

Budget Tracking

General

Budget Tracking | General

Anomaly Detection

General

Anomaly Detection | General

Automation Jobs

General

Automation Jobs | General

Change History

Automation Jobs | Change History

URL & Page Checkers

Automation Jobs | URL & Page Checkers

Local & Reviews

Automation Jobs | Local & Reviews

Search Console

Automation Jobs | Search Console

Insights

Managing Insights

Insights | Managing Insights

Change History

Insights | Change History

URL & Page

Insights | URL & Page

Local & Reviews

Insights | Local & Reviews

Other Insight Types

Insights | Other Insight Types

Local Listings

General

Local Listings | General

Profiles & Content

Local Listings | Profiles & Content

Performance & Activity

Local Listings | Performance & Activity

Media

Local Listings | Media

Categories & Services

Local Listings | Categories & Services

Reviews

General

Reviews | General

Social Posts

General

Social Posts | General

Creating Posts

Social Posts | Creating Posts

Managing Posts

Social Posts | Managing Posts

Data Warehouse

Pipelines

Data Warehouse | Pipelines

Access & Credits

Data Warehouse | Access & Credits

Source Fields

Data Warehouse | Source Fields

Data Studio

Data Warehouse | Data Studio

BigQuery

Data Warehouse | BigQuery

General

Clients | General

General

Integrations | General

MCP

Integrations | MCP

Webhook — Automation Payloads

Integrations | Webhook — Automation Payloads

Webhook — Local & Reviews

Integrations | Webhook — Local & Reviews

Webhook — Other

Integrations | Webhook — Other

Account & Billing

Settings | Account & Billing

Users

Settings | Users

Comments & Notes

Settings | Comments & Notes

Notifications

Settings | Notifications

FAQ

Settings | FAQ

Other

Settings | Other

Account Settings

Settings | Account & Billing

Acknowledging and Resolving Insights

Insights | Managing Insights

Add comment from Slack

Integrations | General

Add comment from Zapier

Settings | Comments & Notes

Adding a User

Settings | Users

AI Analysis Generation

Reports | Creating & Sharing

AI Credits

AI | General

AI Models

AI | General

Analysis Card

Reports | Content Cards

Anomalies Bulk Action

Anomaly Detection | General

Anomaly Algorithm

Anomaly Detection | General

Anomaly Detection

Anomaly Detection | General

Anomaly Detection Insight

Insights | Other Insight Types

Anomaly Detection Settings

Anomaly Detection | General

Anomaly Detection Webhook Payload

Integrations | Webhook — Other

Anomaly Job Common Errors

Anomaly Detection | General

An overview of Local Listings

Local Listings | General

An overview of Reviews

Reviews | General

Area Chart Card

Reports | Chart Cards

Attributes

Local Listings | Profiles & Content

Automatic Schema Updates

Data Warehouse | Pipelines

Automation: Facebook Ads Destination URL Checker

Integrations | Webhook — Automation Payloads

Automation: Google Ads Change History

Integrations | Webhook — Automation Payloads

Automation: Google Ads Destination URL Checker

Integrations | Webhook — Automation Payloads

Automation: Google Analytics Change History

Integrations | Webhook — Automation Payloads

Automation: Google Business Profile Answer

Integrations | Webhook — Local & Reviews

Automation: Google Business Profile Change History

Integrations | Webhook — Automation Payloads

Automation: Google Business Profile Pending Updates

Integrations | Webhook — Local & Reviews

Automation: Google Business Profile Question

Integrations | Webhook — Local & Reviews

Automation: Google Review

Integrations | Webhook — Local & Reviews

Automation: Google Review Change History

Integrations | Webhook — Automation Payloads

Automation Job Common Errors

Automation Jobs | General

Automation Jobs

Automation Jobs | General

Automation: Microsoft Ads Destination URL Checker

Integrations | Webhook — Automation Payloads

Automation: Page Status Checker

Integrations | Webhook — Automation Payloads

Automation: Robots.txt Change Detection

Integrations | Webhook — Automation Payloads

Automations Bulk Action

Automation Jobs | General

Automation: Search Console Activity

Integrations | Webhook — Automation Payloads

Automation: Search Console Keyword Movement

Integrations | Webhook — Automation Payloads

Auto Resolving

Insights | Managing Insights

Bar Chart Card

Reports | Chart Cards

Branding

Reports | Creating & Sharing

Budget Campaign Dynamic Filter

Budget Tracking | General

Budget Common Errors

Budget Tracking | General

Budget history

Budget Tracking | General

Budgets Bulk Actions

Budget Tracking | General

Budget Settings

Budget Tracking | General

Budget Status

Budget Tracking | General

Budget Tracker Webhook Payload

Integrations | Webhook — Other

Budget Tracking

Budget Tracking | General

Budget Webhook URL

Budget Tracking | General

Bulk Action

Local Listings | General

Bulk Upload Images

Local Listings | Media

Calendar

Social Posts | General

Cancel Subscription

Settings | Account & Billing

Card Chat

Reports | Editing

Card Data Filters

Reports | Creating & Sharing

Categories

Local Listings | Categories & Services

Categories Bulk Action

Local Listings | Categories & Services

Category and Service List

Local Listings | Categories & Services

Change email address

Settings | Users

Client Filtering

Clients | General

Client Settings

Clients | General

Column Chart Card

Reports | Chart Cards

Comment notification settings

Settings | Notifications

Connect a data source

Data Sources | General

Connecting to Slack

Integrations | General

Connecting Zapier

Integrations | General

Connect Jepto MCP to Claude

Integrations | MCP

Connect to Google BigQuery

Data Sources | Connections

Connect to Google Business Profile

Data Sources | Connections

Connect to Google Sheets

Data Sources | Connections

Connect to Instagram Ads

Data Sources | Connections

Connect to LinkedIn Ads

Data Sources | Connections

Connect to Microsoft Ads

Data Sources | Connections

Connect to TikTok Ads

Data Sources | Connections

Connect to X (Formerly Twitter) Ads

Data Sources | Connections

Cover Photo Guide

Local Listings | Media

Create a Report

Reports | Creating & Sharing

Create Theme

Reports | Report Config

Creating a Card

Reports | Creating & Sharing

Creating a Client

Clients | General

Creating a Data Studio Report

Data Warehouse | Data Studio

Creating and configuring a KPI

KPI Forecasting | General

Creating a Pipeline

Data Warehouse | Pipelines

Creating a Social Post

Social Posts | Creating Posts

Creating Automation Jobs

Automation Jobs | General

Creating Social Posts with Liquid

Social Posts | Creating Posts

Custom Visualizations

Reports | Editing

Data Model

Data Sources | General

Data Query

Data Sources | General

Data Sources

Data Sources | General

Data Studio Parameters

Data Warehouse | Data Studio

Data Warehouse Access Control

Data Warehouse | Access & Credits

Data Warehouse Common Errors

Data Warehouse | Access & Credits

Data Warehouse Credits

Data Warehouse | Access & Credits

Delete or Archive Client

Clients | General

Deleting a User

Settings | Users

Difference between comments and notes

Settings | Comments & Notes

Disconnect Data Source Connection

Data Sources | General

Donut Chart Card

Reports | Chart Cards

Draft Posts

Social Posts | Managing Posts

Edit default Data Studio Report

Data Warehouse | Data Studio

Edit Email and Slack Notification

Settings | Notifications

Editing a Pipeline

Data Warehouse | Pipelines

Editing or Deleting a Comment

Settings | Comments & Notes

Email Notifications

Settings | Notifications

Email preferences

Settings | Notifications

Error Posts

Social Posts | Managing Posts

Execution Webhook

Data Warehouse | Pipelines

Facebook Ads Data Source Metrics

KPI Forecasting | Metrics by Source

Facebook Ads destination URL checker

Automation Jobs | URL & Page Checkers

Facebook Ads Fields

Data Warehouse | Source Fields

Facebook Ads KPI

KPI Forecasting | Metrics by Source

Fast Reply

Reviews | General

Filter Date Range

Reports | Report Config

Filter Dropdown List

Reports | Report Config

Formula

Data Sources | Fields & Formulas

Getting Started

Settings | FAQ

Google Account Connection

Data Sources | Connections

Google Account Not Connecting

Data Sources | Connections

Google Ads change history

Automation Jobs | Change History

Google Ads change history Insight

Insights | Change History

Google Ads Data Source Metrics

KPI Forecasting | Metrics by Source

Google Ads destination URL checker

Automation Jobs | URL & Page Checkers

Google Analytics change history

Automation Jobs | Change History

Google Analytics Data Source Metrics

KPI Forecasting | Metrics by Source

Google BigQuery Permissions

Data Warehouse | BigQuery

Google Business Profile Change History

Automation Jobs | Change History

Google Business Profile Data Source Metrics

KPI Forecasting | Metrics by Source

Google Business Profile Fields

Data Warehouse | Source Fields

Google Business Profile Listing Answers

Automation Jobs | Local & Reviews

Google Business Profile Listing Questions

Automation Jobs | Local & Reviews

Google Business Profile Pending Updates

Automation Jobs | Local & Reviews

Google Business Profile Reporting Timezone

Data Warehouse | Source Fields

Google Drive Account Connection

Data Sources | Connections

Google Review Change History

Automation Jobs | Change History

Google Review Change History Insight

Insights | Change History

Google Reviews

Automation Jobs | Local & Reviews

Google Reviews Insight

Insights | Local & Reviews

Google Search Console Configuration Options

Data Warehouse | Source Fields

Google Search Console Fields

Data Warehouse | Source Fields

Google Sheets for Budgets

Budget Tracking | General

Google Sheets format

KPI Forecasting | Settings & Status

Grant access to BigQuery data

Data Warehouse | Data Studio

History

Data Chat | General

How to add a comment

Settings | Comments & Notes

How to apply variables to your profiles

Local Listings | Profiles & Content

HTML Card

Reports | Content Cards

Image Card

Reports | Content Cards

Image Categories

Local Listings | Media

Insights

Insights | Managing Insights

Insights Bulk Actions

Insights | Managing Insights

Integrations

Integrations | General

Jepto MCP Server Overview

Integrations | MCP

KPI Campaign Dynamic Filter

KPI Forecasting | Settings & Status

KPI Common Errors

KPI Forecasting | Settings & Status

KPI Forecasting

KPI Forecasting | General

KPI Forecasting Webhook Payload

Integrations | Webhook — Other

KPI history

KPI Forecasting | Settings & Status

KPI Insight

Insights | Other Insight Types

KPIs Bulk Actions

KPI Forecasting | General

KPI Seasonal Trends

KPI Forecasting | Seasonality

KPI Status

KPI Forecasting | Settings & Status

KPI Yearly Seasonality

KPI Forecasting | Seasonality

Line Chart Card

Reports | Chart Cards

Local Listings Activity

Local Listings | Performance & Activity

Local Listings Performance

Local Listings | Performance & Activity

Local Profiles

Local Listings | Profiles & Content

Logo Photo Guide

Local Listings | Media

Make Authentication

Integrations | MCP

Managed BigQuery

Data Warehouse | BigQuery

Management - Data Studio Connector Fields

Data Warehouse | Data Studio

MCP Connector

Data Chat | General

Media

Local Listings | Media

Media Bulk Actions

Local Listings | Media

Media Description

Local Listings | Media

Media file requirements

Social Posts | General

Media file requirements

Local Listings | Media

Media Pacing

Local Listings | Media

Memories

Data Chat | General

Microsoft Ads Data Source Metrics

KPI Forecasting | Metrics by Source

Microsoft Ads destination URL checker

Automation Jobs | URL & Page Checkers

Number Chart Card

Reports | Chart Cards

OAuth & Authentication

Integrations | MCP

Opening Hours Display

Local Listings | Profiles & Content

Overview

Data Chat | General

Page status checker

Automation Jobs | URL & Page Checkers

Page status checker Insight

Insights | URL & Page

Palettes

Reports | Report Config

Performance

Reviews | General

Pipeline Extensions

Data Warehouse | Pipelines

Platforms

Local Listings | General

Portfolio

Clients | General

Post Types

Social Posts | Creating Posts

Preview a Report

Reports | Creating & Sharing

Published Posts

Social Posts | Managing Posts

Questions and Answers

Local Listings | Profiles & Content

Refresh data source fields

Data Warehouse | Data Studio

Refresh Report Data

Reports | Report Config

Related Insights

Insights | Managing Insights

Removed Reviews

Reviews | General

Report Chat

Reports | Editing

Report Master & Linking

Reports | Creating & Sharing

Report Settings

Reports | Report Config

Resolve or Acknowledge via 3rd parties

Insights | Managing Insights

Review Activity

Reviews | General

Review Replies

Reviews | General

Review Reply AI Models

Reviews | General

Robots.txt change detection

Automation Jobs | URL & Page Checkers

Robots.txt change detection Warning

Automation Jobs | URL & Page Checkers

Rolling Average

KPI Forecasting | Settings & Status

Rules

Clients | General

Scatter Chart Card

Reports | Chart Cards

Scheduled Posts

Social Posts | Managing Posts

Search Console Activity

Automation Jobs | Search Console

Search Console Activity Insight

Insights | Other Insight Types

Search Console keyword movement

Automation Jobs | Search Console

Search Console keyword movement Insight

Insights | Other Insight Types

Search Keywords

Local Listings | General

Select a Client

Clients | General

Send a Report

Reports | Creating & Sharing

Sending Slack Notifications

Integrations | General

Services

Local Listings | Categories & Services

Services Bulk Action

Local Listings | Categories & Services

Settings

Settings | Account & Billing

Share a Report

Reports | Creating & Sharing

Social Posts

Social Posts | General

Submit a Ticket

Settings | FAQ

Subscribe or Update Plan

Settings | Account & Billing

Table Card

Reports | Content Cards

Template Data Sources

Data Sources | Fields & Formulas

Templates

Reports | Report Config

Text Card

Reports | Content Cards

Transfer ownership

Settings | Account & Billing

Unified Fields

Data Sources | Fields & Formulas

Unreplied Reviews

Reviews | General

Update Account Profile

Settings | Account & Billing

Update Client Profile

Clients | General

Update Data Studio Fields

Data Warehouse | Data Studio

Update user password

Settings | Users

Users

Settings | Users

UTM Tagging

Social Posts | General

Variables

Settings | Other

Visibility

Local Listings | Performance & Activity

Watchers

Settings | Comments & Notes

Webhook Logs

Integrations | Webhook — Other

Choose article...

OAuth & Authentication


When you connect an external AI assistant to Jepto's remote MCP server at https://mcp.jepto.com, the assistant must sign in as you. That sign-in uses the same Jepto account login as the web app. This article explains what that OAuth flow does, what it authorizes, and what it does not expose to the AI client.

This is not the same as connecting Google Ads, Meta, or other marketing platforms inside Jepto. Those platform connections are a separate layer. MCP authentication only proves who you are in Jepto; platform credentials stay on Jepto's servers.

Two layers of authentication

LayerWhat it isWhen it happens
1. Jepto MCP OAuthSign-in to Jepto when an MCP client connects to mcp.jepto.com. Issues a short-lived access token tied to your user and account.When you click Connect in Claude (or another supported MCP client) and complete the Jepto login screen.
2. Platform connectionsOAuth tokens for Google Ads, Meta, GA4, Search Console, and other sources stored in Jepto when you connect data sources in the app.Under Data Sources → Connections in Jepto, before MCP can query or act on that platform's data.

MCP tools only work on data and connections your Jepto account already has. Signing in to MCP does not connect new marketing platforms by itself.

What happens when you connect

Jepto MCP OAuth flow (simplified)

MCP client
You add https://mcp.jepto.com and click Connect
↓ browser redirect
Jepto sign-in
Same email and password as the Jepto web app
↓ successful login
Access token issued
OAuth/OIDC token returned to the MCP client
↓ on every tool call
MCP server
Validates token and runs tools with your permissions
  1. You register the server URL https://mcp.jepto.com in your MCP client
  2. When you connect, the client opens a browser window to Jepto's login page.
  3. After you sign in, Jepto issues an OAuth access token (JWT) to the client through the standard MCP remote-server OAuth flow.
  4. On every subsequent MCP request, the client sends that token in an Authorization: Bearer … header.
  5. Jepto validates the token on each request before the request reaches the Jepto MCP server.
  6. Each tool call is scoped to your Jepto Account and user, enforcing the same boundaries as logging into the App.

How the client discovers OAuth

When you enter https://mcp.jepto.com, the MCP client fetches well-known metadata from Jepto's server:

  • https://mcp.jepto.com/.well-known/oauth-protected-resource - identifies the protected MCP resource and authorization server.
  • https://mcp.jepto.com/.well-known/oauth-authorization-server - lists authorize and token endpoints, supported scopes, PKCE (S256), and grant types (authorization_code, refresh_token).

Sign-in and token exchange use Jepto's secure endpoints:

  • Authorize: https://auth.jepto.com/oauth2/authorize
  • Token (code exchange and refresh): https://auth.jepto.com/oauth2/token

There is no API-key or client-credentials path for MCP. If a client cannot do OAuth with PKCE, it cannot connect to Jepto MCP.

What is never shared with the AI client

Security is designed so the LLM and MCP client never receive long-lived platform secrets:

  • Google / Meta / other platform OAuth tokens — stored in Jepto when you connect data sources. When MCP runs analytics or confirmed ad-platform actions, Jepto securely loads credentials server-side and passes them only to internal adapter services — not to Claude, ChatGPT, or the conversation.
  • Refresh tokens and API keys — never appear in tool results, MCP App UI payloads, or model context.

How platform credentials relate to MCP

For MCP to query Google Ads spend or pause a campaign, that client must already have an active Google Ads data source in Jepto.

If a platform is not connected, analytics tools return empty or error responses for that source — MCP cannot bypass Jepto's connection setup. Connect platforms first under Connect a data source.

Refresh token process

After the first sign-in, your MCP client holds two tokens from the OAuth client used for connectors:

  • Access token — sent as Authorization: Bearer … on every MCP tool call. Lifetime: 60 minutes.
  • Refresh token — kept by the MCP client only; Jepto MCP never receives it. Lifetime: 30 days from issuance.

Getting an access token yourself

If you are building or debugging an MCP client, you can complete the OAuth token exchange yourself after the browser authorize step. The examples below show the exact POST requests to Jepto's token endpoint and how to use the returned access_token on MCP calls.

After browser sign-in, exchange the authorization code at Jepto's token endpoint. Use the access_token from the response as Authorization: Bearer … on MCP requests to https://mcp.jepto.com. Do not send the refresh token to MCP.

Request — exchange authorization code

POST · application/x-www-form-urlencoded

POST https://auth.jepto.com/oauth2/token
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code
&client_id=7p119e6f9379mlho57pcuhmb6v
&code=AUTHORIZATION_CODE_FROM_REDIRECT
&redirect_uri=https%3A%2F%2Fmcp.jepto.com%2Foauth%2Fcallback
&code_verifier=PKCE_CODE_VERIFIER_FROM_CLIENT

Response (abbreviated)

200 · JSON

{
  "access_token": "eyJraWQiOiJ...",
  "refresh_token": "eyJjdHkiOiJ...",
  "id_token": "eyJraWQiOiJ...",
  "token_type": "Bearer",
  "expires_in": 3600
}

Request — refresh access token

POST · when access token expires (~60 min)

POST https://auth.jepto.com/oauth2/token
Content-Type: application/x-www-form-urlencoded

grant_type=refresh_token
&client_id=7p119e6f9379mlho57pcuhmb6v
&refresh_token=STORED_REFRESH_TOKEN
  • redirect_uri must match the authorize step exactly. For manual testing, use https://mcp.jepto.com/oauth/callback or your MCP product's registered callback.
  • code_verifier is the PKCE secret your client generated; it pairs with code_challenge sent to the authorize URL.
  • access_token is what MCP expects — not the id_token.

What happens when the access token expires

Well-behaved MCP clients refresh automatically before or right after the access token expires:

  1. The client POSTs to https://auth.jepto.com/oauth2/token with grant_type=refresh_token, the stored refresh token, and the OAuth client id.
  2. Jepto OAuth servers return a new access token.
  3. The client continues MCP calls with the new Bearer token.

When you must sign in again

Full browser sign-in is required only when:

  • The refresh token has expired (after ~30 days without a successful refresh), or
  • The client lost stored tokens (disconnect, new device, cleared credentials), or
  • Refresh fails (revoked session, password change, or client bug) and tool calls then fail with authentication errors until you reconnect.

Token lifetime summary

TokenLifetimeWho holds itUsed for
Access token60 minutesMCP clientEvery MCP request (Bearer header); validated by Jepto before tools run
Refresh token30 daysMCP client onlySilent renewal via /oauth2/token

Note: The Jepto web app (app.jepto.com) uses a different Cognito app client with a 15-minute access token. MCP connectors use the OAuth client above — do not mix the two when debugging session length.

Troubleshooting authentication

SymptomLikely causeWhat to try
Login screen loops or failsWrong Jepto credentials; SSO policy; browser blocking redirectsSign in at app.jepto.com first; allow pop-ups/redirects; reset password if needed
Connected but every tool errorsExpired token; client not on allowed listDisconnect and reconnect; confirm you use https://mcp.jepto.com exactly
"Session not authenticated" / "sign in again"Bearer token missing or expiredRe-run Connect in the MCP client
Tools work but no ad platform dataPlatform not connected for that clientConnect the data source in Jepto; verify client has an active datasource
Action fails after confirmationStale platform OAuth in Jepto (not MCP login)Re-authenticate the platform under Data Sources → Connections
Related Articles
Was this article helpful?
Nice one!

Thanks a lot for your feedback! If you’d like a member of our support team to respond to you, please send a message here

Please try again

Oops! Something went wrong while submitting the form.

Sorry about that. What did you find most unhelpful?
Nice one!

Thanks a lot for your feedback! If you’d like a member of our support team to respond to you, please send a message here

Please try again

Oops! Something went wrong while submitting the form.