The resource indicator ties a token to the specific server it was issued for, so a token obtained for Dust cannot be replayed against a different MCP endpoint that trusts the same authorisation server. Few servers enforce it. Combined with the data-handling position — no training, nothing retained by providers — this is a connection built for organisations that have to answer questions about where their data went.
Dust's endpoint over their agent platform. Their documentation describes capability areas for the first version and states that the exact tools may change, so no fixed list is published.
The capability areas Dust documents for this version. Because they say the surface will evolve, the honest thing to work against is the live tool list rather than a snapshot.
OAuth 2.0 with PKCE, dynamic client registration and a required resource parameter. Dust states customer data is never used to train models and that third-party providers hold nothing.
Paste a URL, then authorize — add the endpoint to your client, then approve the OAuth consent screen
