Endpoint
https://api.pocketsflow.com/mcp — a Streamable HTTP MCP endpoint. Add the
URL to your AI app, then sign in to Pocketsflow and click Allow access.
No API key to create or copy.Authentication
You don’t need an API key to connect an AI app. The server speaks standard MCP authorization (OAuth 2.1), so any client that supports it handles the sign-in for you: Claude, ChatGPT, Cursor, VS Code, Gemini CLI, Windsurf, or an agent you build with an MCP SDK. Nothing is tied to one AI vendor.1
Add the server URL
Paste
https://api.pocketsflow.com/mcp into your app as a remote MCP
server or custom connector (see Connect an agent).
Leave any authentication, token, or header fields empty.2
Sign in to Pocketsflow
When the app connects, your browser opens
app.pocketsflow.com/oauth/consent. Sign in with your usual Pocketsflow
login if asked, and check which app is asking and which account it will
use.3
Click Allow access
You’re sent back to the app and the Pocketsflow tools appear. Click
Cancel instead to refuse; nothing is created.
MCP: <app name>, in the mode your account is in at that
moment (live or test; the consent screen shows a Test mode badge). The key
itself never leaves Pocketsflow: the app only receives OAuth tokens with the
mcp:tools scope.
- Access tokens last one hour and are bound to
https://api.pocketsflow.com/mcp. - Refresh tokens renew them automatically. Each one is single-use and rotates on every refresh; one left unused for 30 days expires, and the app asks you to sign in again.
- To disconnect an app, delete its
MCP: …key under Developers → API keys. Access stops on the next request.
For MCP client developers
Clients discover everything from the server. An unauthenticated request to/mcp returns 401 with
WWW-Authenticate: Bearer resource_metadata="https://api.pocketsflow.com/.well-known/oauth-protected-resource", scope="mcp:tools".
Supported client styles:
- Dynamic client registration (RFC 7591) or Client ID Metadata
Documents (an HTTPS URL as
client_id, MCP 2025-11-25). - Redirect URIs: HTTPS (web apps),
http://127.0.0.1/localhost/[::1]on any port (CLIs, RFC 8252), and app schemes such ascursor://orvscode://(desktop apps). - Public clients with PKCE
S256;client_idin the body or via HTTP Basic. Grant typesauthorization_codeandrefresh_token. The RFC 8707resourceparameter is optional; when sent it must behttps://api.pocketsflow.com/mcp. - The sign-in request is valid for 5 minutes. After that, the consent screen asks the user to start the connection again from their AI tool.
Alternative: API key (headless / CI)
For scripts, CI jobs, server-side agents, the@pocketsflow/mcp stdio bridge, or clients without OAuth
support, you can skip the sign-in and send an API key instead. Create one under
Developers → API keys and send it on every request:
Every tool call is executed as your account, however you connect. Deleting
the key stops access immediately.
Connect an agent
Add the server URL, then sign in and click Allow access when the app asks.With an API key (headless / CI)
Only for clients that can’t run the sign-in, or for automation. These send the key on every request instead of signing in.@pocketsflow/mcp only for clients that speak local stdio MCP; it always
authenticates with the POCKETSFLOW_API_KEY environment variable.
Agent skill
Install the companion skill from skills.sh:Available tools
Tools mirror the public API, namedverb_resource (for example list_orders,
create_product, cancel_subscription). Only operations that work with
API-key auth are exposed.
update_pricing is an alias of update_product for agents that ask to change
price. Creator payouts remain dashboard/JWT-only and are not exposed as MCP
tools.The Payments tools expose the unified ledger (one-time purchases and
subscription renewals), and the subscriber tools return live membership
status plus full payment history — the same data as
GET /payments and GET /subscriptions/subscribers.
Ask things like “how much recurring revenue did I collect last month?” or
“list my past-due subscribers.”The tool list is generated from the public API contract, so it stays in sync
as the API evolves. Call
tools/list on the endpoint (or check your agent’s
tool panel) for the authoritative, current set.How it works
The MCP server is part of the Pocketsflow backend — there is no separate service to run or host. Each tool call is forwarded to the corresponding public REST endpoint with the connection’s API key (for an OAuth connection, itsMCP: … key), so validation, permissions, and per-account data scoping are identical to calling the API directly.
The transport is stateless Streamable HTTP: the agent POSTs JSON-RPC messages (initialize, tools/list, tools/call) to /mcp and receives a JSON response. No session state is stored server-side.
You can call it directly without an agent framework. curl can’t run the
browser sign-in, so send an API key on every request:
list_orders accepts pagination filters;
create_subscription_offer accepts offer fields; update_pricing /
update_product accept the product id plus fields to change). Errors surface
as MCP tool errors carrying the same status and message the REST endpoint would
return (for example a 401 for an invalid key). Use a pk_test_… key to
exercise everything safely against sandbox data first.
Related topics
- MCP setup guide — Claude Desktop, Cursor, ChatGPT
- API reference — the underlying REST endpoints
- Authentication & security
- Webhooks & API overview