Drift MCP authentication

Clients discover the authorization server from a 401 challenge, register dynamically (RFC 7591), and send the user to a Drift consent page. PKCE S256 is mandatory.

Access tokens last one hour; refresh tokens rotate on every use and reuse revokes the authorization. Users revoke clients anytime from Connections → Authorized apps.