Skip to content
xNotePadAI
📝 App

MCP Authentication

August 23, 2026 · 4 min read

Every MCP request to xNotePadAI requires authentication. Here's exactly how it works — from token generation to revocation — so you understand what happens when your AI agent connects.

Token Format

Tokens are UUID-pairs: two UUIDs concatenated with a hyphen (~73 characters). Generated client-side using crypto.randomUUID() — 244 bits of cryptographic entropy. Example format:

xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx-xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

How Authentication Works

1. Agent sends: Authorization: Bearer <token>

2. Server computes SHA-256(token)

3. Server looks up hash in mcp_tokens table

4. If found + not revoked → extract tenant_id from that row

5. All subsequent operations scoped to that tenant

The plain-text token never touches the database. Only the SHA-256 hash is stored. If the database is compromised, attackers get hashes that cannot be reversed into working tokens.

Getting a Token

Tokens are pre-generated when you first visit xNotePadAI. No signup, no email, no manual generation step:

Using the Token

Every MCP request includes the token as a Bearer header:

POST /api/mcp/
Authorization: Bearer your-token-here
Content-Type: application/json

Revocation

Revocation is instant and irreversible:

Multiple Tokens

You can generate additional tokens for different agents (Settings → Connected Apps → enter a name → Generate). Each token is independent — revoking one doesn't affect others. This lets you give Claude one token and Cursor another, and revoke either without disrupting the other.

What Tokens DON'T Do