Get a PAT (token exchange)
A Personal Access Token (PAT) authorizes your MCP client against POST / GET /mcp.
Exchange the same Sports API credentials you use for REST: client_id plus secret_key
(or the alias client_secret in JSON).
Mint PATs from your backend, CI, or a secure shell using the examples below, not from MCP client configuration files.
Request
Section titled “Request”| Method / URL | POST https://<mcp-host>/api/v1/token |
| Content-Type | application/json |
| Auth | None (credentials in JSON body) |
| Field | Required | Description |
|---|---|---|
client_id | yes | Sports API client ID |
secret_key | yes | Sports API secret (alias: client_secret) |
label | no | Optional label for your records (string, max 256 characters) |
{ "client_id": "YOUR_CLIENT_ID", "secret_key": "YOUR_SECRET_KEY", "label": "cursor-laptop"}Example with curl:
curl -sS -X POST "https://mcp.statscore.com/api/v1/token" \ -H "Content-Type: application/json" \ -d '{"client_id":"YOUR_CLIENT_ID","secret_key":"YOUR_SECRET_KEY","label":"ci-agent"}'The server applies rate limiting per IP before parsing the body, then per client_id after validation.
Success (201 Created)
Section titled “Success (201 Created)”{ "token": "<PAT>", "expires_at": null, "warning": "Zapisz token teraz. Nie będzie ponownie wyświetlony."}The live API may use slightly different punctuation in warning; the meaning is unchanged.
token: shown once. UseAuthorization: Bearer <PAT>on/mcp(see Connect a client).expires_at: ISO timestamp ornullif the PAT does not expire.
Errors
Section titled “Errors”| HTTP | error | Meaning |
|---|---|---|
| 400 | missing_fields | Missing client_id or secret, or invalid JSON body |
| 400 | invalid_label | label is not a string or is longer than 256 characters |
| 403 | invalid_credentials | OAuth probe failed (wrong ID/secret or API denied) |
| 409 | tenant_slug_conflict | Account configuration conflict; contact Statscore support |
| 502 | statscore_unavailable | Statscore OAuth/API unreachable or transport error |
| 429 | rate_limit_exceeded | Too many exchange attempts (per IP or per client_id) |
| 500 | (varies) | Server misconfiguration |
Responses never include secret_key.
Rate limits (defaults)
Section titled “Rate limits (defaults)”Limits apply per rolling window. If you hit 429 often under normal integration load, contact Statscore support.
| Limit | Default | Applies to |
|---|---|---|
| Token exchange window | 15 minutes | POST /api/v1/token |
| Token exchanges per IP | 30 | Per window |
Token exchanges per client_id | 10 | Per window |
/mcp request window | 1 minute | Tool calls |
/mcp requests | 120 | Per PAT per window (unauthenticated calls may be limited per IP) |
Repeat exchange
Section titled “Repeat exchange”Each successful call with the same client_id and secret can issue a new PAT.
Store the new token and update your MCP client configuration.
Revoke old PATs you no longer need if your workflow creates many tokens over time.
Related
Section titled “Related”- Connect a client - use the PAT on
/mcp - Get a token (REST) - short-lived Sports API token (different from PAT)