Connecting an MCP client
Issue a workspace API key or connect via OAuth, then configure Claude, Codex, Antigravity, Copilot, or any other MCP client against the Epox MCP server.
Two ways to authenticate
Every call to https://app.epox.ai/api/mcp needs a bearer credential. There are two ways to get one, and once you have it, the calls you make look identical either way.
- Workspace API key — a long-lived secret you create once in Settings → Developers → API Keys and paste into your client's config. This is what every example below uses; it's the right choice for coding agents, CLIs, and scripts.
- OAuth — for MCP clients that do their own dynamic client registration and browser consent (Claude.ai's and ChatGPT's Connectors pickers, for example). The server advertises RFC 8414 authorization-server metadata and RFC 9728 protected-resource metadata, so a compliant client discovers everything it needs automatically; you approve the connection on Epox's own consent screen instead of pasting a secret. Manage or revoke an approved connection from Settings → Developers → MCP.
Create a workspace API key
- Open Settings → Developers → API Keys and click Create key.
- Give it a label that identifies the agent or integration (e.g. "Codex development", "Nightly automation script") — keys belong to the workspace, not to the person who created them, and the label is how a teammate will recognize it later.
- Optionally set an expiry.
- Check Allow generation only if this agent should be able to start queued pack generations and consume credits. Leave it unchecked for a read-only integration — you can always create a second, more privileged key later instead of widening this one.
- Copy the secret immediately. It's shown once, in the form
epox_wsk_live_…, and cannot be displayed again — if you lose it, revoke it and create a new one.
Configure your client
Every client needs the same two pieces of information: the server URL and an Authorization: Bearer header carrying your key.
Server URL: https://app.epox.ai/api/mcp
Authorization: Bearer epox_wsk_live_…Claude Code (CLI)
claude mcp add --transport http epox https://app.epox.ai/api/mcp \
--header "Authorization: Bearer epox_wsk_live_…"Claude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"epox": {
"url": "https://app.epox.ai/api/mcp",
"headers": { "Authorization": "Bearer epox_wsk_live_…" }
}
}
}Codex — add to ~/.codex/config.toml:
[mcp_servers.epox]
url = "https://app.epox.ai/api/mcp"
headers = { Authorization = "Bearer epox_wsk_live_…" }Antigravity — Settings → MCP Servers, add to mcp_config.json:
{
"mcpServers": {
"epox": {
"url": "https://app.epox.ai/api/mcp",
"headers": { "Authorization": "Bearer epox_wsk_live_…" }
}
}
}GitHub Copilot — add to .vscode/mcp.json:
{
"servers": {
"epox": {
"type": "http",
"url": "https://app.epox.ai/api/mcp",
"headers": { "Authorization": "Bearer epox_wsk_live_…" }
}
}
}Any other MCP-capable client works the same way: a streamable-HTTP (or HTTP+SSE) server at the URL above, with the bearer header set. You can also find these snippets in-app under Settings → Developers → API Docs, pre-filled once you have a key.
Authentication
- Every request needs
Authorization: Bearer <credential>— API key or OAuth access token, checked the same way. - A request with no
Originheader (true of essentially every non-browser MCP client) is accepted normally. A request that does carry anOriginmust match the platform's own origin — this only matters if you're calling the endpoint from inside a browser page, which is unusual for MCP. - An invalid, revoked, or expired credential returns HTTP 401.
- Once connected, call
tools/listto see exactly which tools your credential's scopes allow — the list itself isn't scope-filtered, but attempting to call a tool outside your scopes fails with a JSON-RPC error, not a silent no-op.
Verifying the connection
Once configured, ask your agent to call epox_workspace_summary (every scope can reach it) — a successful response confirms the URL, header, and credential are all correct before you try anything that spends credits. See Developer overview for the full request/response shape, and the tool-reference pages for every other tool.