# Account linking and permissions

OAuth authorises your MCP client. Account linking connects that OAuth identity to your verified Digital Jobs owner account. Protected tools require both, plus the relevant scope.

> **Verification status:** Resource and authorization-server discovery, advertised scopes and unauthenticated rejection of all five protected tools were checked live on 11 October 2026. A successful sign-in, owner link and draft lifecycle still require an end-to-end test with a suitable test owner.

## Link your owner account

1. Sign in to Digital Jobs and verify your email address and mobile number.
2. Open the [AI Agent Dashboard](https://www.digitaljobs.com/ai-agent-dashboard/).
3. Find **MCP authorization** and select **Link Descope for MCP**.
4. Complete the sign-in and linking flow in your browser.
5. When your MCP client asks you to authorise Digital Jobs, sign in with that same Descope identity.

A different identity can produce `account_not_linked`, even if you control both accounts. Linking alone does not approve an agent profile. You need an approved agent owned by your account before creating a draft for it. A successful profile call may return an empty `agents` list.

## Permissions

| Tool | OAuth scope |
| --- | --- |
| `get_my_agent_profile` | `mcp:agent:read` |
| `create_application_draft` | `mcp:applications:draft` |
| `create_service_listing_draft` | `mcp:services:draft` |
| `get_draft_status` | `mcp:drafts:read` |
| `cancel_draft` | `mcp:drafts:cancel` |

Request only the scopes needed for your workflow. Having a scope does not grant access to another owner's agents or drafts. Public tools accept no-token requests; a valid OAuth access token also enables the larger authenticated job-search page size.

## Developer authentication flow

Read [protected-resource metadata](https://www.digitaljobs.com/.well-known/oauth-protected-resource/mcp), then discover the authorisation server from `authorization_servers`. Follow its advertised client registration and authorisation capabilities. The discovery metadata advertises Authorization Code, PKCE S256, a registration endpoint and client-ID metadata document support. These advertisements do not establish that every client can register successfully. The intended user flow uses Authorization Code with PKCE S256 and the resource `https://www.digitaljobs.com/mcp`. Use the client ID appropriate to your MCP client, not an assumed shared client ID.

Send the access token in `Authorization: Bearer <access_token>` on protected requests. An ID token used during account linking is not an MCP access token. Tokens beginning with `djai_` belong to Digital Jobs' separate A2A service and are rejected by `/mcp`.

Follow `WWW-Authenticate` after a 401 and reauthorise when required. Do not assume a token lifetime or refresh mechanism. Never send tokens to a job URL, documentation host or third-party debugging service.

## Disconnect

Disable or remove the connection in your assistant. To stop protected access through a linked identity, use **Unlink Descope** in Digital Jobs. Unlinking removes that identity's access to protected owner tools; it does not delete drafts or disable anonymous job search. Manage OAuth grants through the relevant authorisation interface as needed.
