blog/developers·Sep 24, 2026·5 min·by the eroq team
The eroq MCP server now signs you in — OAuth, no key to paste
How "Connect eroq" works in Claude, ChatGPT, Claude Code, Cursor and VS Code. OAuth 2.1 with PKCE, dynamic client registration, a key minted per app and revocable in the dashboard — and what changed in the tools.
Until this month, connecting eroq to an AI app meant pasting an API key into a config file — or, for apps that could not send headers, putting the key in the URL. It worked and it was the wrong shape: a key in a chat app's settings is a secret in the wrong place, and nobody rotates it. The remote MCP server at https://eroq.ai/mcp now runs a proper sign-in. Click Connect, sign in on eroq.ai, click Allow, done. This is how it works, what the app gets, and what changed in the tools while we were there.
What the app gets
When you click Allow, eroq mints an ordinary eroq_sk_… key for that app, named after it — « Claude (connected) », « Cursor on studio-mac (connected) » — and hands it to the app as its access token. That key is listed under Developers → API keys like any other. Revoke it there and the connection stops, immediately; reconnect and a new one is minted. Reconnecting the same app name replaces its previous key, so a lost laptop is one revoke away from clean.
There is no session table, no refresh token, no second identity: the app calls /mcp and /v1 with a key, so billing, workspace roles, rate limits, bans and revocation work exactly as they do for a key you made by hand. The MCP page has a button per app.
The flow, for the curious
It is standard OAuth 2.1, which is why every client that speaks the MCP auth spec works without code on our side per client:
- The app calls
POST /mcpwith no token and gets a401with aWWW-Authenticateheader pointing at/.well-known/oauth-protected-resource, which points at/.well-known/oauth-authorization-server. - The app registers itself —
POST /oauth/register(RFC 7591 dynamic registration) with its name and redirect URIs — and gets aclient_id. ChatGPT registers differently: itsclient_idis a URL to a metadata document it hosts, which we fetch and verify. - It opens
GET /oauth/authorizein your browser with a PKCE challenge (S256, mandatory). You sign in if needed, see « App wants to use your eroq account », click Allow. - It exchanges the code at
POST /oauth/tokenwith the PKCE verifier and gets the key. Codes live two minutes and are bound to the client, the redirect URI and the challenge. POST /oauth/revokewith the key when you disconnect from the app's side.
The client_id is a signed blob of the registration — anyone on the internet can register, so a table would only collect spam — and the authorization code is the key itself, sealed, bound and short-lived. Nothing new to provision; nothing to leak from a database that does not exist.
Keys still work. Scripts and clients without an OAuth flow send Authorization: Bearer eroq_sk_…, and clients that cannot send headers use https://eroq.ai/mcp/<key> — that URL is then a secret. Codex CLI uses the eroq CLI as a local stdio server with a key in its environment.
Per app
- Claude (web and desktop): one click on the Claude page opens « Add custom connector » with the eroq URL filled in; Add, Connect, Allow.
- ChatGPT: Developer mode (Plus, Pro, Business, Enterprise, Edu), create an app with the URL, pick OAuth. The ChatGPT guide walks it.
- Claude Code:
claude mcp add --transport http eroq https://eroq.ai/mcp, then/mcp→ eroq → Authenticate. Or the plugin. - Cursor and VS Code: one-click install links on their pages; the sign-in runs on first use. The editors guide has both.
What changed in the tools
The tool list is the same ten — generate_image, get_image_status, generate_video, get_video_status, generate_speech, enhance_prompt, list_models, list_voices, list_characters, get_account — with three changes worth knowing if you built on them:
Images come back as pictures. generate_image queues the render (images are asynchronous on /v1 now, one job per take, like video), polls it inside the call — well under the request ceiling — and returns the image inline plus a signed link valid thirty minutes; the render also stays in your library. Chat apps display tool images and rarely fetch a URL, so inline is what shows up in the conversation. A slow cold start hands back a job id for get_image_status, which is free. New aspect parameter: 1:1, 3:4, 4:3, 9:16, 16:9, same price.
Video knows the lineup. generate_video takes a model from the 16 engines (default Seedance 2.0 Mini), a resolution from what that engine serves, an audio switch on engines with a soundtrack, and reference_image_url as the first frame on engines with image-to-video. Prices in list_models come from the billing function, never a typed number: a five-second clip is 45 credits on the default engine, 170 on Kling 3.0, 135 on Veo 3.1 Fast. Some engines need a plan, and the list says which.
ChatGPT sees the auth. Tools declare their OAuth security scheme in the listing, which is what makes ChatGPT show its « connect » UI; other clients ignore the field.
FAQ
Is the access token a real API key?
Yes — an ordinary key, named after the app, in your workspace. That is the point: one kind of credential, one place to revoke it, the same billing and roles everywhere.
Can I still use a key I made by hand?
Yes, as a Bearer header, or in the URL for clients that cannot send headers. OAuth is the default for apps that support it, not a requirement.
What does the app see of my account?
Only what its key can call: the generation tools, the free lookups, and the balance. It never sees your password; sign-in happens on eroq.ai.
Does connecting cost anything?
No. Calls bill the studio prices — 10 credits for a Krea 2 image, 45 for a five-second Seedance 2.0 Mini clip — and failed renders refund themselves.
Pick your app on eroq.ai/mcp; the MCP docs have the header and CLI variants.
Make this with the models behind the post — start with 50 free credits , or browse every engine and its price .