# The eroq MCP server now signs you in — OAuth, no key to paste

> How "Connect eroq" works in Claude, ChatGPT, Claude Code, Cursor and VS Code. OAuth 2.1 with PKCE, dynamic client registration, a key minted per app and revocable in the dashboard — and what changed in the tools.

Published 2026-09-24 · eroq.ai — canonical: https://eroq.ai/blog/mcp-sign-in-oauth-no-api-key


Until this month, connecting eroq to an AI app meant pasting an API key into a config file — or, for apps that could not send headers, putting the key in the URL. It worked and it was the wrong shape: a key in a chat app's settings is a secret in the wrong place, and nobody rotates it. The remote MCP server at `https://eroq.ai/mcp` now runs a proper sign-in. Click Connect, sign in on eroq.ai, click Allow, done. This is how it works, what the app gets, and what changed in the tools while we were there.

## What the app gets

When you click Allow, eroq mints an ordinary `eroq_sk_…` key for that app, named after it — **« Claude (connected) »**, **« Cursor on studio-mac (connected) »** — and hands it to the app as its access token. That key is listed under Developers → API keys like any other. Revoke it there and the connection stops, immediately; reconnect and a new one is minted. Reconnecting the *same* app name replaces its previous key, so a lost laptop is one revoke away from clean.

There is no session table, no refresh token, no second identity: the app calls `/mcp` and `/v1` with a key, so billing, workspace roles, rate limits, bans and revocation work exactly as they do for a key you made by hand. The [MCP page](/mcp) has a button per app.

## The flow, for the curious

It is standard OAuth 2.1, which is why every client that speaks the MCP auth spec works without code on our side per client:

1. The app calls `POST /mcp` with no token and gets a `401` with a `WWW-Authenticate` header pointing at `/.well-known/oauth-protected-resource`, which points at `/.well-known/oauth-authorization-server`.
2. The app **registers itself** — `POST /oauth/register` (RFC 7591 dynamic registration) with its name and redirect URIs — and gets a `client_id`. ChatGPT registers differently: its `client_id` is a URL to a metadata document it hosts, which we fetch and verify.
3. It opens `GET /oauth/authorize` in your browser with a PKCE challenge (S256, mandatory). You sign in if needed, see « *App* wants to use your eroq account », click Allow.
4. It exchanges the code at `POST /oauth/token` with the PKCE verifier and gets the key. Codes live two minutes and are bound to the client, the redirect URI and the challenge.
5. `POST /oauth/revoke` with the key when you disconnect from the app's side.

The `client_id` is a signed blob of the registration — anyone on the internet can register, so a table would only collect spam — and the authorization code is the key itself, sealed, bound and short-lived. Nothing new to provision; nothing to leak from a database that does not exist.

Keys still work. Scripts and clients without an OAuth flow send `Authorization: Bearer eroq_sk_…`, and clients that cannot send headers use `https://eroq.ai/mcp/<key>` — that URL is then a secret. Codex CLI uses the [eroq CLI](/blog/claude-code-and-the-eroq-cli) as a local stdio server with a key in its environment.

## Per app

- **Claude** (web and desktop): one click on the [Claude page](/plugins/claude) opens « Add custom connector » with the eroq URL filled in; Add, Connect, Allow.
- **ChatGPT**: Developer mode (Plus, Pro, Business, Enterprise, Edu), create an app with the URL, pick OAuth. The [ChatGPT guide](/blog/use-eroq-in-chatgpt) walks it.
- **Claude Code**: `claude mcp add --transport http eroq https://eroq.ai/mcp`, then `/mcp` → eroq → Authenticate. Or the [plugin](/blog/claude-code-plugin-and-skill).
- **Cursor** and **VS Code**: one-click install links on their pages; the sign-in runs on first use. The [editors guide](/blog/ai-images-and-video-from-claude-code-cursor-vscode) has both.

## What changed in the tools

The tool list is the same ten — `generate_image`, `get_image_status`, `generate_video`, `get_video_status`, `generate_speech`, `enhance_prompt`, `list_models`, `list_voices`, `list_characters`, `get_account` — with three changes worth knowing if you built on them:

**Images come back as pictures.** `generate_image` queues the render (images are asynchronous on `/v1` now, one job per take, like video), polls it inside the call — well under the request ceiling — and returns the image *inline* plus a signed link valid thirty minutes; the render also stays in your library. Chat apps display tool images and rarely fetch a URL, so inline is what shows up in the conversation. A slow cold start hands back a job id for `get_image_status`, which is free. New `aspect` parameter: `1:1`, `3:4`, `4:3`, `9:16`, `16:9`, same price.

**Video knows the lineup.** `generate_video` takes a `model` from the 16 engines (default [Seedance 2.0 Mini](/models/seedance-2-0-mini)), a `resolution` from what that engine serves, an `audio` switch on engines with a soundtrack, and `reference_image_url` as the first frame on engines with image-to-video. Prices in `list_models` come from the billing function, never a typed number: a five-second clip is 45 credits on the default engine, 170 on [Kling 3.0](/models/kling-3), 135 on [Veo 3.1 Fast](/models/veo-3-1-fast). Some engines need a plan, and the list says which.

**ChatGPT sees the auth.** Tools declare their OAuth security scheme in the listing, which is what makes ChatGPT show its « connect » UI; other clients ignore the field.

## FAQ

### Is the access token a real API key?

Yes — an ordinary key, named after the app, in your workspace. That is the point: one kind of credential, one place to revoke it, the same billing and roles everywhere.

### Can I still use a key I made by hand?

Yes, as a Bearer header, or in the URL for clients that cannot send headers. OAuth is the default for apps that support it, not a requirement.

### What does the app see of my account?

Only what its key can call: the generation tools, the free lookups, and the balance. It never sees your password; sign-in happens on eroq.ai.

### Does connecting cost anything?

No. Calls bill the studio prices — 10 credits for a Krea 2 image, 45 for a five-second Seedance 2.0 Mini clip — and failed renders refund themselves.

Pick your app on [eroq.ai/mcp](/mcp); the [MCP docs](/docs/mcp) have the header and CLI variants.
