Navigation
Introduction
Connect
Reference
More
Reference
Server and authentication
Technical details on the endpoint, OAuth sign-in and limits.
Server
| Endpoint | https://cite.specterlaw.ai/mcp |
|---|---|
| Transport | Streamable HTTP, MCP 2026-07-28; older clients via initialize |
| Server info | specter-cite |
| Protected Resource Metadata | /.well-known/oauth-protected-resource |
| Authorization Server Metadata | /.well-known/oauth-authorization-server |
| Hosting | EU, data center in Amsterdam |
Authentication
Specter Cite is its own OAuth 2.1 authorization server. Users sign in with their Specter account; the server never sees passwords.
| Flow | Authorization code with PKCE (S256) |
|---|---|
| Client registration | Client ID metadata document (e.g. Claude, ChatGPT) or Dynamic Client Registration |
| Client authentication | none, client_secret_post, client_secret_basic, private_key_jwt |
| Scope | cite:research, plus offline_access for refresh tokens |
| Access token | JWT (ES256), valid for 1 hour |
| Refresh token | rotated on every use; reuse ends the connection |
| Entitlement | re-checked at least every 5 minutes |
Disconnect apps in Specter settings under “Specter Cite”. Access then ends within 5 minutes, as it does when the team cancels the add-on.
Limits
| Requests | 120 per person per minute; beyond that HTTP 429 |
|---|---|
| Text per call | up to 30,000 characters; longer texts in chunks |
| Results | up to 10 with source text, up to 100 in result lists |