What happens after you paste it
Nothing you have to do. The editor calls the endpoint, gets a401 naming a metadata document, reads it, finds the authorization server, registers itself, and starts the flow. Every step is a document.
1
Your browser opens
Tylon asks who you are, the way it always does. This is your own sign-in — the editor never sees it.
2
You pick the boards
The consent screen lists the boards you work on and what you hold on each. Tick one or several: somebody who works on three products should not have to authorize three times to run their day from one terminal.
3
You choose read or write
workspace:read reads. workspace:write also comments and writes down a repository’s conventions — nothing that moves Git.What the connection can do
Exactly what you can, and no more. The role is read from your membership on every single call, per board. A colleague demoted to viewer this morning is a viewer to their editor this afternoon, and somebody removed from a board stops reaching it without anybody remembering that they once connected something. This is the deliberate difference from an API credential, which holds a role of its own because it is nobody.Working across several boards
When a connection reaches more than one, tools that are about a board take aworkspace argument — acme/product, or just product when nothing else you reach answers to it. Leave it out with several and the tool asks rather than guessing.
The details, for a client that wants them
RFC 8414
https://api.tylon.app/.well-known/oauth-authorization-serverRFC 9728
https://api.tylon.app/.well-known/oauth-protected-resource/mcp
Both refusals are capabilities written as refusals: a client reading the metadata learns it must bring PKCE and must not expect a client secret.