Skip to content

Get a PAT (token exchange)

A Personal Access Token (PAT) authorizes your MCP client against POST / GET /mcp. Exchange the same Sports API credentials you use for REST: client_id plus secret_key (or the alias client_secret in JSON).

Mint PATs from your backend, CI, or a secure shell using the examples below, not from MCP client configuration files.

Method / URLPOST https://<mcp-host>/api/v1/token
Content-Typeapplication/json
AuthNone (credentials in JSON body)
FieldRequiredDescription
client_idyesSports API client ID
secret_keyyesSports API secret (alias: client_secret)
labelnoOptional label for your records (string, max 256 characters)
{
"client_id": "YOUR_CLIENT_ID",
"secret_key": "YOUR_SECRET_KEY",
"label": "cursor-laptop"
}

Example with curl:

Terminal window
curl -sS -X POST "https://mcp.statscore.com/api/v1/token" \
-H "Content-Type: application/json" \
-d '{"client_id":"YOUR_CLIENT_ID","secret_key":"YOUR_SECRET_KEY","label":"ci-agent"}'

The server applies rate limiting per IP before parsing the body, then per client_id after validation.

{
"token": "<PAT>",
"expires_at": null,
"warning": "Zapisz token teraz. Nie będzie ponownie wyświetlony."
}

The live API may use slightly different punctuation in warning; the meaning is unchanged.

  • token: shown once. Use Authorization: Bearer <PAT> on /mcp (see Connect a client).
  • expires_at: ISO timestamp or null if the PAT does not expire.
HTTPerrorMeaning
400missing_fieldsMissing client_id or secret, or invalid JSON body
400invalid_labellabel is not a string or is longer than 256 characters
403invalid_credentialsOAuth probe failed (wrong ID/secret or API denied)
409tenant_slug_conflictAccount configuration conflict; contact Statscore support
502statscore_unavailableStatscore OAuth/API unreachable or transport error
429rate_limit_exceededToo many exchange attempts (per IP or per client_id)
500(varies)Server misconfiguration

Responses never include secret_key.

Limits apply per rolling window. If you hit 429 often under normal integration load, contact Statscore support.

LimitDefaultApplies to
Token exchange window15 minutesPOST /api/v1/token
Token exchanges per IP30Per window
Token exchanges per client_id10Per window
/mcp request window1 minuteTool calls
/mcp requests120Per PAT per window (unauthenticated calls may be limited per IP)

Each successful call with the same client_id and secret can issue a new PAT. Store the new token and update your MCP client configuration. Revoke old PATs you no longer need if your workflow creates many tokens over time.