Agent Connect · OAuth + PKCE

Connect an agent. Keep your keys to yourself.

Add Zapros as a remote MCP server, sign in through your browser, and grant only the permissions, models and spending limits the agent needs.

zapros.ai

Remote MCP server

OAuth
MCP endpointHTTPS
https://zapros.ai/mcp
Streamable HTTP · OAuth discovery enabled
PKCE S256ScopedNo secret

Connection check

Checking Zapros and OAuth discovery…
Service…
MCP OAuth…
Management OAuth…

Two OAuth resources

First choose where the app needs access

Zapros issues one grant for MCP and a separate grant for the Management API. These are isolated audiences, not two modes of the same token.

MCP

Agent tools

For Claude, Cursor, Codex, and other MCP clients. The ready-to-use instructions below connect this resource.

OAuth resource
https://zapros.ai/mcp
Protected-resource metadata
https://zapros.ai/.well-known/oauth-protected-resource/mcp
Learn more
Management API

REST for automations

For custom apps and agents that use REST to work with the account, catalog, usage, keys, and compute.

OAuth resource
https://zapros.ai/api/v1/management
Protected-resource metadata
https://zapros.ai/.well-known/oauth-protected-resource/api/v1/management
Learn more

An MCP token is rejected by the Management API, while a management OAuth token cannot be used with MCP or inference endpoints.

Connect

Up and running in a few minutes

The instructions below connect the MCP resource. With OAuth, there is no secret token to create or paste manually.

CLIhttps://zapros.ai/mcp

Claude Code

Add the remote HTTP server, then start browser-based sign-in.

  1. 01Run both commands in your terminal.
  2. 02Sign in to Zapros in the browser and approve the requested access.
  3. 03Return to Claude Code — the connection is saved at user scope.
Terminal
claude mcp add --transport http --scope user zapros https://zapros.ai/mcp
claude mcp login zapros

What happens

Clear authorization without sharing a password

The client discovers OAuth automatically while you stay in control of permissions and spend.

  1. 01

    The client discovers OAuth

    The selected resource challenge points to Zapros protected-resource and authorization-server metadata.

  2. 02

    You sign in to Zapros

    Authorization happens in the browser. Zapros may ask you to verify your email or sign in again when required.

  3. 03

    You set the boundaries

    The consent screen shows scopes, allowed models, the per-request limit and the monthly budget.

  4. 04

    You can revoke access

    The app receives a short-lived resource-bound token. You can disconnect it from your dashboard.

Access control

OAuth by default. A manual token only as a fallback.

Agent Connect separates account sign-in from MCP or Management API access and avoids copying a long-lived secret between applications.

Recommended: Agent Connect OAuth

The client receives access only after you approve it in Zapros.

  • A short-lived access token is bound to exactly one resource.
  • The refresh token rotates on every exchange.
  • Scopes, models and budgets are bounded by the consent policy.
Open connections and revoke access

Fallback: zpm_ management token

For a client without browser OAuth, create a management token with minimal scopes and provide it as a Bearer header.

Manual configuration example
{
  "mcpServers": {
    "zapros": {
      "url": "https://zapros.ai/mcp",
      "headers": {
        "Authorization": "Bearer zpm_your_token"
      }
    }
  }
}

Keep zpm_ in the client's secret storage. Never put it in prompts, a repository, or browser code.

Create a management token
https://zapros.ai/.well-known/oauth-authorization-serverOpen documentation →

Ready to give your agent tools?

Start with OAuth. Your secrets, permissions and spending limits stay under your control.