Agent tools
For Claude, Cursor, Codex, and other MCP clients. The ready-to-use instructions below connect this resource.
- OAuth resource
- https://zapros.ai/mcp
- Protected-resource metadata
- https://zapros.ai/.well-known/oauth-protected-resource/mcp
Add Zapros as a remote MCP server, sign in through your browser, and grant only the permissions, models and spending limits the agent needs.
zapros.ai
Remote MCP server
https://zapros.ai/mcpConnection check
Two OAuth resources
Zapros issues one grant for MCP and a separate grant for the Management API. These are isolated audiences, not two modes of the same token.
Agent tools
For Claude, Cursor, Codex, and other MCP clients. The ready-to-use instructions below connect this resource.
REST for automations
For custom apps and agents that use REST to work with the account, catalog, usage, keys, and compute.
An MCP token is rejected by the Management API, while a management OAuth token cannot be used with MCP or inference endpoints.
Connect
The instructions below connect the MCP resource. With OAuth, there is no secret token to create or paste manually.
Add the remote HTTP server, then start browser-based sign-in.
claude mcp add --transport http --scope user zapros https://zapros.ai/mcp
claude mcp login zaprosWhat happens
The client discovers OAuth automatically while you stay in control of permissions and spend.
The selected resource challenge points to Zapros protected-resource and authorization-server metadata.
Authorization happens in the browser. Zapros may ask you to verify your email or sign in again when required.
The consent screen shows scopes, allowed models, the per-request limit and the monthly budget.
The app receives a short-lived resource-bound token. You can disconnect it from your dashboard.
Access control
Agent Connect separates account sign-in from MCP or Management API access and avoids copying a long-lived secret between applications.
The client receives access only after you approve it in Zapros.
For a client without browser OAuth, create a management token with minimal scopes and provide it as a Bearer header.
{
"mcpServers": {
"zapros": {
"url": "https://zapros.ai/mcp",
"headers": {
"Authorization": "Bearer zpm_your_token"
}
}
}
}Keep zpm_ in the client's secret storage. Never put it in prompts, a repository, or browser code.
Create a management tokenStart with OAuth. Your secrets, permissions and spending limits stay under your control.