Skip to content

MCP connections

The hosted MCP server with OAuth and the Connections page are not built yet. Use the stdio server with an API key today.

This feature is not built yet. This article says what works today.

The hosted Avaloi MCP server at mcp.avaloi.com, its OAuth sign-in, the consent screen, and the Connections page in the dashboard are not built yet. Today an AI agent reaches Avaloi through the stdio MCP server that runs on your computer with an API key.

What to do today

Connect an agent. Build the stdio server from the Avaloi repository and point your MCP client at it with an API key. The key's scopes are the ceiling on what the agent can do. See Connect an AI agent with the MCP server.

See who has access. Each agent uses a named API key. Open API keys in the dashboard to see the keys, their scopes, and when each was last used. The activity log shows the agent's calls under the key name with the MCP client's name, for example "Claude Desktop".

Revoke access. Revoke the key under API keys, or call DELETE /v1/api-keys/{id}. The agent loses access within 5 seconds. Create a new key with fewer scopes if you want to keep the agent on a shorter leash.

Scope it tightly. Give an agent sites:read alone to let it look and not touch. Add sites:write for cache, PHP, and deploy changes. Leave danger:destroy off unless you want it to delete or reset sites, and remember that a key with that scope needs an expiry.

Not yet

The hosted MCP server will arrive as one feature. When it does:

  • You will add Avaloi to a remote MCP client by its address, mcp.avaloi.com, without building anything.
  • You will sign in with OAuth instead of pasting an API key.
  • A consent screen will show the scopes the client asks for, and you will approve or trim them before the connection works.
  • A Connections page in the dashboard will list every connected client, when it last acted, and what it may do.
  • You will revoke a connection from that page with one action.

Quick answers

Can I use the hosted server now? No. Use the stdio server with an API key.

How do I see what an agent did? Open the activity log. Calls appear under the key name with the MCP client's name and version.

How do I cut an agent off right now? Revoke its API key. Access ends within 5 seconds.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.