Universal MCP
Use the Streamable HTTP MCP endpoint shown on the API Vault home page. OAuth protected-resource and authorization-server discovery are published on the same API Vault front door.
Use the Streamable HTTP MCP endpoint shown on the API Vault home page. OAuth protected-resource and authorization-server discovery are published on the same API Vault front door.
Connector OAuth uses authorization code + PKCE. Sign in to API Vault, review the requesting client, scopes and authority, then approve the bounded connector capability. You do not paste a stored provider credential into the consent page.
Register a trusted browser worker and create a profile for the websites you need. Start the worker, sign in yourself in its visible browser, then mark the profile ready. Passwords, passkeys, CAPTCHA, MFA, cookies and browser storage remain on that worker.
Confirm the client supports remote Streamable HTTP MCP, then repeat OAuth authorization or re-scan tools. API Vault intentionally returns HTTP 401 for unauthenticated protected calls and rejects malformed protocol requests rather than silently weakening authentication.
Revoke the AI identity, connector capability, provider grant or browser profile from API Vault. A browser profile can also be put back into human-login mode so new delegated browser work is blocked until you mark it ready again.
Do not include API keys, bearer tokens, authorization codes, refresh tokens, worker keys or screenshots containing credentials in a support report. Provide only timestamps, client name, HTTP status, correlation ID and non-secret error text.