Authorization screen
An authorization screen, or OAuth consent screen, is the page where a person signs in to a service and approves an application's access to their account, so that the application receives a token rather than their password. IZeat shows its own authorization screen when an assistant connects: the customer signs in with Google, an email and password, or a six-digit code by email, and approves; the assistant then holds a token scoped to IZeat, and no password ever passes through it.
The screen exists because a remote MCP server is reachable by anyone who learns its address, and a link carrying a token would be a password by another name. IZeat's server is an OAuth 2.1 resource server with its own authorization server: an assistant identifies itself, asks for scopes, and receives a token minted for IZeat alone, which cannot be replayed elsewhere. The customer sees who is asking and what for before saying yes.
For the customer the screen is one tap with Google or a code from their inbox, once per assistant. What it buys is a connection they can see and revoke on their Assistants page, an assistant that never sees their sign-in, and a food and weight history that is not one leaked URL away from being read by someone else.
Updated