Epox Docs
Open app

Connecting an MCP client

Issue a workspace API key or connect via OAuth, then configure Claude, Codex, Antigravity, Copilot, or any other MCP client against the Epox MCP server.

Two ways to authenticate

Every call to https://app.epox.ai/api/mcp needs a bearer credential. There are two ways to get one, and once you have it, the calls you make look identical either way.

  • Workspace API key — a long-lived secret you create once in Settings → Developers → API Keys and paste into your client's config. This is what every example below uses; it's the right choice for coding agents, CLIs, and scripts.
  • OAuth — for MCP clients that do their own dynamic client registration and browser consent (Claude.ai's and ChatGPT's Connectors pickers, for example). The server advertises RFC 8414 authorization-server metadata and RFC 9728 protected-resource metadata, so a compliant client discovers everything it needs automatically; you approve the connection on Epox's own consent screen instead of pasting a secret. Manage or revoke an approved connection from Settings → Developers → MCP.

Create a workspace API key

  1. Open Settings → Developers → API Keys and click Create key.
  2. Give it a label that identifies the agent or integration (e.g. "Codex development", "Nightly automation script") — keys belong to the workspace, not to the person who created them, and the label is how a teammate will recognize it later.
  3. Optionally set an expiry.
  4. Check Allow generation only if this agent should be able to start queued pack generations and consume credits. Leave it unchecked for a read-only integration — you can always create a second, more privileged key later instead of widening this one.
  5. Copy the secret immediately. It's shown once, in the form epox_wsk_live_…, and cannot be displayed again — if you lose it, revoke it and create a new one.

Configure your client

Every client needs the same two pieces of information: the server URL and an Authorization: Bearer header carrying your key.

text
Server URL:     https://app.epox.ai/api/mcp
Authorization:  Bearer epox_wsk_live_…

Claude Code (CLI)

bash
claude mcp add --transport http epox https://app.epox.ai/api/mcp \
  --header "Authorization: Bearer epox_wsk_live_…"

Claude Desktop — add to claude_desktop_config.json:

json
{
  "mcpServers": {
    "epox": {
      "url": "https://app.epox.ai/api/mcp",
      "headers": { "Authorization": "Bearer epox_wsk_live_…" }
    }
  }
}

Codex — add to ~/.codex/config.toml:

toml
[mcp_servers.epox]
url = "https://app.epox.ai/api/mcp"
headers = { Authorization = "Bearer epox_wsk_live_…" }

Antigravity — Settings → MCP Servers, add to mcp_config.json:

json
{
  "mcpServers": {
    "epox": {
      "url": "https://app.epox.ai/api/mcp",
      "headers": { "Authorization": "Bearer epox_wsk_live_…" }
    }
  }
}

GitHub Copilot — add to .vscode/mcp.json:

json
{
  "servers": {
    "epox": {
      "type": "http",
      "url": "https://app.epox.ai/api/mcp",
      "headers": { "Authorization": "Bearer epox_wsk_live_…" }
    }
  }
}

Any other MCP-capable client works the same way: a streamable-HTTP (or HTTP+SSE) server at the URL above, with the bearer header set. You can also find these snippets in-app under Settings → Developers → API Docs, pre-filled once you have a key.

Authentication

  • Every request needs Authorization: Bearer <credential> — API key or OAuth access token, checked the same way.
  • A request with no Origin header (true of essentially every non-browser MCP client) is accepted normally. A request that does carry an Origin must match the platform's own origin — this only matters if you're calling the endpoint from inside a browser page, which is unusual for MCP.
  • An invalid, revoked, or expired credential returns HTTP 401.
  • Once connected, call tools/list to see exactly which tools your credential's scopes allow — the list itself isn't scope-filtered, but attempting to call a tool outside your scopes fails with a JSON-RPC error, not a silent no-op.

Verifying the connection

Once configured, ask your agent to call epox_workspace_summary (every scope can reach it) — a successful response confirms the URL, header, and credential are all correct before you try anything that spends credits. See Developer overview for the full request/response shape, and the tool-reference pages for every other tool.

Was this guide useful?Your feedback helps us refine the documentation.