https://api.pocketsflow.com/mcp exposes the full public API as tools — create
products, read orders, issue refunds, manage webhooks, send newsletters, and
more — scoped to your account. It works with any AI app or model provider that
speaks MCP, not one vendor.
Endpoint
https://api.pocketsflow.com/mcp — Streamable HTTP. Add the URL, then sign
in to Pocketsflow and click Allow access. No API key needed.1. How signing in works
Most MCP clients support MCP authorization (OAuth): Claude, ChatGPT, Cursor, VS Code, Gemini CLI, Windsurf, and agents built on the official MCP SDKs. With them you only add the server URL:- Add
https://api.pocketsflow.com/mcpto your app (step 2 below). Leave any token or header fields empty. - When you connect, your browser opens Pocketsflow. Sign in if asked and check which app is asking.
- Click Allow access. You’re sent back to the app and the tools appear.
MCP: <app name> for that
connection, in the mode your account is in (live or test), and the app only
ever receives short-lived tokens that refresh on their own. Delete that key
under Developers → API keys to disconnect it.
Nothing is tied to one AI vendor. Pocketsflow accepts every standard way an
MCP client identifies itself: dynamic client registration, Client ID Metadata
Documents, web redirects, loopback redirects on any port (CLIs), and app
schemes such as cursor:// or vscode:// (desktop apps).
Alternative: API key (headless / CI)
For scripts, CI jobs, the@pocketsflow/mcp stdio bridge, or a client that can
only send a static header, create a key yourself and skip the sign-in. These
are the same API keys the REST API uses.
- Open the dashboard → Developers → API keys.
- Create a key. Prefer
pk_test_…while you set things up. - Copy the key once — it is shown only at creation.
Send it on every request:
2. Add the server to your client
Pick your client. The server URL is all you need: connect, sign in, and click Allow access. The API-key variants are only for headless setups or clients without OAuth.- Claude
- Claude Desktop
- Cursor
- ChatGPT
Claude’s hosted custom connectors use OAuth. You only paste the server URL,
then approve the connection with your Pocketsflow login. No API key to
create or copy.
- Open Customize → Connectors.
- Click + → Add custom connector.
- Name it Pocketsflow and enter
https://api.pocketsflow.com/mcpas the remote MCP server URL. - Leave Advanced settings empty and click Add.
- Click Connect. Pocketsflow opens in your browser: sign in if asked, check that Claude is the app asking, and click Allow access.
MCP: Claude for the
connection. Delete it under Developers → API keys to disconnect.
Claude discovers the OAuth endpoints automatically, so there is no URL key
or custom-header field to fill in.After connecting, enable Pocketsflow from the + → Connectors menu in
a new chat and ask Claude to list your products.3. First tool call walkthrough
Once the client shows Pocketsflow tools, verify the connection with a read-only call before anything that writes.1
Confirm the account
Ask:
Using the Pocketsflow tools, call get_account and summarize who I’m
authenticated as.
You should see your store / account details. A 401 or authentication error
means the connection isn’t signed in: reconnect from the client and click
Allow access again. With an API key, check that the header is present,
typed correctly, and the key wasn’t revoked, then reload the client.2
List products
Ask:
List my products with list_products.
Empty is fine in a fresh test account — a successful empty list still proves
auth and tool discovery work. (list_products takes no filters today.)3
Create something in test mode
In test mode (your account was in test mode when you clicked
Allow access, or you use a
pk_test_… key):Create a $19 product called “MCP Starter Kit” and give me a checkout link.The agent should call
create_product then
create_checkout_session and return a hosted checkout URL. Open it to
confirm the sandbox product.Handy prompts
4. Verify without an AI client
You can hit the same endpoint withcurl to isolate client vs. server issues.
curl can’t run the browser sign-in, so this uses an API key:
Troubleshooting
Related topics
- MCP server — tool catalog and transport details
- Authentication & security
- Developer setup
- Claude Code + Pocketsflow
- Cursor + Pocketsflow
- Windsurf + Pocketsflow