1. Setup
Salla Platform Docs
  • Getting Started
    • Overview
    • Usage
  • Setup
    • Install Via Plugin
    • Authorization
    • Skills Only
    • Connect MCP
  • Reference
    • Skills Reference
    • MCP Tools Reference
  • Support
    • Troubleshooting
Merchant
Merchant
  • Merchant API
  • Embedded SDK
  • Salla OAuth 2.0
Storefront
Storefront
  • Twilight Engine
  • Twilight SDK
  • Web Components
  • Ecommerce Events
  • Component Bundle
  • Checkout APIs
  • Change Log
App Functions
Partner APIs
Partner APIs
  • App API
  • Shipments & Fulfillment APIs
  • Salla AWB
  • Recurring Payments API
  • Billing System Salla partners
  • Communication Apps
Dev Tools
Dev Tools
  • Partners Agent Kit
  • Salla Apps Playbook
  • Salla CLI
Merchant
Merchant
  • Merchant API
  • Embedded SDK
  • Salla OAuth 2.0
Storefront
Storefront
  • Twilight Engine
  • Twilight SDK
  • Web Components
  • Ecommerce Events
  • Component Bundle
  • Checkout APIs
  • Change Log
App Functions
Partner APIs
Partner APIs
  • App API
  • Shipments & Fulfillment APIs
  • Salla AWB
  • Recurring Payments API
  • Billing System Salla partners
  • Communication Apps
Dev Tools
Dev Tools
  • Partners Agent Kit
  • Salla Apps Playbook
  • Salla CLI
Salla - Opensource
Salla - Developers Community
  1. Setup

Authorization

The Partners MCP uses OAuth 2.1 with PKCE to verify your identity and keep your partner account secure. This page explains how the flow works and what to expect during and after the login process.
Authroization Page

The Authorization Flow#

When you connect the Partners MCP for the first time, your client opens a browser window and walks you through a one-time login against the Salla Partners Portal.
No credentials are stored in your editor or config files. Instead, the login mints a short-lived access token and a refresh token that your client manages automatically.
Here's what happens step by step:
1
Initiate the connection
Your client sends an authorization request to https://partners.mcp.salla.dev using PKCE. A code verifier and code challenge are generated locally so the exchange is secure even over HTTP.
2
Log in via browser
A browser window opens and prompts you to log in to your Salla Partner account. If you're already logged in, this step completes automatically.
3
Token is issued
After a successful login, the Partners Portal issues an access token and a refresh token. Your client stores these and uses them for every subsequent
MCP request.
4
Automatic refresh
Sessions last around 14 days. Your client refreshes the access token silently in the background. You only need to re-authorize when the refresh token itself expires.

Re-authorizing#

If your session expires or you switch partner accounts, re-authorization is straightforward. Run the same command or flow you used to connect initially and complete the browser login again.
ClientHow to re-authorize
Claude CodeRun /mcp and follow the browser prompt
CursorGo to Settings → MCP and reconnect
Claude DesktopGo to Settings → Connectors and reconnect
Other clientsRemove and re-add the MCP server entry in your config
Re-authorizing does not affect your apps, settings, or any data on the Partners Portal. It only refreshes the token your client uses to authenticate MCP requests.
Modified at 2026-06-28 14:58:49
Previous
Install Via Plugin
Next
Skills Only