Skip to main content
The Pocketsflow MCP server exposes the same public HTTP API you see at api.pocketsflow.com/docs as Model Context Protocol tools. Point any MCP-capable agent, from any AI provider (Claude, ChatGPT, Cursor, VS Code, Gemini CLI, Windsurf, your own app), at it, approve the connection with your Pocketsflow login, and it can create products, read orders, issue refunds, manage webhooks, send newsletters, and more — on your behalf, scoped to your account.

Endpoint

https://api.pocketsflow.com/mcp — a Streamable HTTP MCP endpoint. Add the URL to your AI app, then sign in to Pocketsflow and click Allow access. No API key to create or copy.

Authentication

You don’t need an API key to connect an AI app. The server speaks standard MCP authorization (OAuth 2.1), so any client that supports it handles the sign-in for you: Claude, ChatGPT, Cursor, VS Code, Gemini CLI, Windsurf, or an agent you build with an MCP SDK. Nothing is tied to one AI vendor.
1

Add the server URL

Paste https://api.pocketsflow.com/mcp into your app as a remote MCP server or custom connector (see Connect an agent). Leave any authentication, token, or header fields empty.
2

Sign in to Pocketsflow

When the app connects, your browser opens app.pocketsflow.com/oauth/consent. Sign in with your usual Pocketsflow login if asked, and check which app is asking and which account it will use.
3

Click Allow access

You’re sent back to the app and the Pocketsflow tools appear. Click Cancel instead to refuse; nothing is created.
When you click Allow access, Pocketsflow creates a dedicated API key for that app, named MCP: <app name>, in the mode your account is in at that moment (live or test; the consent screen shows a Test mode badge). The key itself never leaves Pocketsflow: the app only receives OAuth tokens with the mcp:tools scope.
  • Access tokens last one hour and are bound to https://api.pocketsflow.com/mcp.
  • Refresh tokens renew them automatically. Each one is single-use and rotates on every refresh; one left unused for 30 days expires, and the app asks you to sign in again.
  • To disconnect an app, delete its MCP: … key under Developers → API keys. Access stops on the next request.

For MCP client developers

Clients discover everything from the server. An unauthenticated request to /mcp returns 401 with WWW-Authenticate: Bearer resource_metadata="https://api.pocketsflow.com/.well-known/oauth-protected-resource", scope="mcp:tools". Supported client styles:
  • Dynamic client registration (RFC 7591) or Client ID Metadata Documents (an HTTPS URL as client_id, MCP 2025-11-25).
  • Redirect URIs: HTTPS (web apps), http://127.0.0.1 / localhost / [::1] on any port (CLIs, RFC 8252), and app schemes such as cursor:// or vscode:// (desktop apps).
  • Public clients with PKCE S256; client_id in the body or via HTTP Basic. Grant types authorization_code and refresh_token. The RFC 8707 resource parameter is optional; when sent it must be https://api.pocketsflow.com/mcp.
  • The sign-in request is valid for 5 minutes. After that, the consent screen asks the user to start the connection again from their AI tool.

Alternative: API key (headless / CI)

For scripts, CI jobs, server-side agents, the @pocketsflow/mcp stdio bridge, or clients without OAuth support, you can skip the sign-in and send an API key instead. Create one under Developers → API keys and send it on every request:
Every tool call is executed as your account, however you connect. Deleting the key stops access immediately.
Treat API keys like passwords. An agent connected with a pk_live_… key can create and delete real data. Use a pk_test_… key while developing, keep keys out of git, and prefer a dedicated, revocable key per integration.

Connect an agent

Add the server URL, then sign in and click Allow access when the app asks.

With an API key (headless / CI)

Only for clients that can’t run the sign-in, or for automation. These send the key on every request instead of signing in.
Prefer the remote HTTP URL when your client supports it. Use @pocketsflow/mcp only for clients that speak local stdio MCP; it always authenticates with the POCKETSFLOW_API_KEY environment variable.

Agent skill

Install the companion skill from skills.sh:
The skill teaches agents when to use MCP tools versus the REST API, and the first-product / sales-check workflows. Once connected, the agent lists the available tools automatically. Ask it things like “list my last 10 orders”, “create a $29 product called Starter Kit”, or “refund order ord_123”. For step-by-step copy-paste setup (Claude, Claude Desktop, Cursor, ChatGPT) plus an auth and first-call walkthrough, see the MCP setup guide. From Products → Create New in the dashboard, select an assistant under Use your favorite AI. The prompt includes the MCP endpoint, asks for the details of your one-time product or subscription, and requests confirmation before creating it. Claude and ChatGPT can open with the prompt prefilled; for Cursor, Grok, OpenCode, DeepSeek, GLM, and Kimi, copy the prompt and paste it into the assistant. Connect MCP first when prompted: add the server URL, then sign in and click Allow access. Only clients without OAuth support need an API key, and it goes in the client’s MCP settings. Never paste an API key into a chat or a prompt.

Available tools

Tools mirror the public API, named verb_resource (for example list_orders, create_product, cancel_subscription). Only operations that work with API-key auth are exposed.
update_pricing is an alias of update_product for agents that ask to change price. Creator payouts remain dashboard/JWT-only and are not exposed as MCP tools.
The Payments tools expose the unified ledger (one-time purchases and subscription renewals), and the subscriber tools return live membership status plus full payment history — the same data as GET /payments and GET /subscriptions/subscribers. Ask things like “how much recurring revenue did I collect last month?” or “list my past-due subscribers.”
The tool list is generated from the public API contract, so it stays in sync as the API evolves. Call tools/list on the endpoint (or check your agent’s tool panel) for the authoritative, current set.

How it works

The MCP server is part of the Pocketsflow backend — there is no separate service to run or host. Each tool call is forwarded to the corresponding public REST endpoint with the connection’s API key (for an OAuth connection, its MCP: … key), so validation, permissions, and per-account data scoping are identical to calling the API directly. The transport is stateless Streamable HTTP: the agent POSTs JSON-RPC messages (initialize, tools/list, tools/call) to /mcp and receives a JSON response. No session state is stored server-side. You can call it directly without an agent framework. curl can’t run the browser sign-in, so send an API key on every request:
Because each tool maps to the underlying REST endpoint, tool arguments mirror the endpoint’s parameters (for example list_orders accepts pagination filters; create_subscription_offer accepts offer fields; update_pricing / update_product accept the product id plus fields to change). Errors surface as MCP tool errors carrying the same status and message the REST endpoint would return (for example a 401 for an invalid key). Use a pk_test_… key to exercise everything safely against sandbox data first.