Integration Guide
MCP endpoints, authentication methods, and connection examples for integrating AI agents with MCP Gateway.
MCP Endpoint URL
Each MCP gets a unique endpoint URL, shown as Quilr gateway on its server card in Settings > AI Gateway > MCP Gateway and on the user dashboard at mcpgateway.quilr.ai. Point your AI agent to this URL to connect. The base domain is typically https://mcpgateway.quilr.ai or https://mcpgateway.quilrai.com, but it can vary by environment.
https://mcpgateway.quilr.ai/<your-mcp-slug>/mcp
Authentication Methods
MCP Gateway separates the credential your AI client uses to reach the gateway from the credential the gateway uses to reach the upstream MCP server.
Client to Gateway
API Token Authentication
Send a Bearer token with a user identifier header for per-user tracking.
Authorization: Bearer <token>
mcpuser: user@company.com
- Create API tokens in the server's Settings > API tokens (not shown on OAuth servers). See API Tokens.
- Each token is scoped to a specific agent
- The
mcpuserheader identifies the end user for per-user tracking - The
mcpuseremail must belong to an allowed company domain
Gateway OAuth Proxy Tokens
OAuth-capable MCP clients can authenticate to the gateway through the gateway's OAuth endpoints. After the user signs in, the token endpoint returns a stable proxy token. The proxy token is scoped to the MCP server, or to OneMCP for the /quilrone/mcp endpoint.
OAuth Passthrough
In OAuth passthrough mode, the gateway advertises or relays the upstream OAuth metadata and the AI client obtains an upstream access token itself. The gateway accepts that upstream Bearer token on the direct per-MCP endpoint, forwards it to the upstream MCP server, and uses token claims such as email, preferred_username, upn, or sub for logging when available.
OAuth passthrough MCPs are not exposed through OneMCP and do not use gateway token storage, refresh, user dashboard connections, or proxy tokens.
Gateway to Upstream MCP
To choose a mode when you add a server, see Adding MCP Servers. For manual OAuth setup steps, see MCP Provider Setup. For OneMCP unified access, memory tools, and inline authentication, see OneMCP.
Non-OAuth MCPs can also receive the authenticated Quilr user identity in a gateway-generated X-User-Claims JSON header. Turn it on with Forward user claims in the server's Settings > General. It works for direct MCP and OneMCP requests and is off by default. See Claims forwarding for configuration, schema, and trust requirements.
Token-Based Connection Example
# Connect to MCP endpoint with token auth
curl -X POST https://mcpgateway.quilr.ai/your-mcp-slug/mcp \
-H "Content-Type: application/json" \
-H "Authorization: Bearer <your-api-token>" \
-H "mcpuser: user@company.com" \
-d '{
"jsonrpc": "2.0",
"method": "tools/list",
"id": 1
}'
Connect an AI client
Use the OneMCP URL from the user dashboard (for example https://mcpgateway.quilr.ai/quilrone/mcp) to get every gateway-managed MCP through one connection, or a single MCP's Quilr gateway URL. OAuth passthrough MCPs are only available on their own URL (see OneMCP).
The gateway speaks MCP over Streamable HTTP. Clients authenticate with OAuth: on the first request the gateway answers 401 with a pointer to its OAuth metadata, the client registers itself, and your browser opens to sign in with your company account. There is no token to copy. Before an MCP's tools work, connect it once on the user dashboard (or through the in-chat connector card).
- Cursor
- Claude Desktop / Claude.ai
- VS Code
- Claude Code
- Other clients
Connect Cursor
Add the server to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json in a project:
{
"mcpServers": {
"quilr-onemcp": {
"url": "https://mcpgateway.quilr.ai/quilrone/mcp"
}
}
}
Open Cursor's MCP settings, start the sign-in for quilr-onemcp, and complete it in the browser.
Connect Claude Desktop and Claude.ai
Remote MCP servers are added as connectors, not in claude_desktop_config.json (that file is for local servers).
- In Claude, open Settings > Connectors and add a custom connector.
- Paste the OneMCP URL and save.
- Click Connect and sign in when the browser opens.
A connector added on Claude.ai is also available in Claude Desktop for the same account.
Connect VS Code
Add the server to .vscode/mcp.json in a workspace (or run MCP: Add Server for your user profile):
{
"servers": {
"quilr-onemcp": {
"type": "http",
"url": "https://mcpgateway.quilr.ai/quilrone/mcp"
}
}
}
Start the server from the file or the MCP server list, and sign in when prompted.
Connect Claude Code
claude mcp add --transport http quilr-onemcp https://mcpgateway.quilr.ai/quilrone/mcp
Then run /mcp in Claude Code, select quilr-onemcp and authenticate.
Connect other MCP clients
Any client that supports remote MCP servers over Streamable HTTP with OAuth (protected resource metadata and dynamic client registration) can connect with just the URL.
Clients without OAuth can call a single non-OAuth MCP's URL with an API token and the mcpuser header. OneMCP accepts only tokens from the OAuth sign-in, not API tokens.
Check the connection
-
Without signing in, confirm the URL is right. A
401with aWWW-Authenticateheader that containsresource_metadatameans you reached the gateway:curl -i -X POST https://mcpgateway.quilr.ai/quilrone/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' -
After signing in, list the client's tools. With OneMCP and dynamic tool calling on, expect
list_mcp_connections,find_relevant_toolsandcall_tool, plus the memory tools when Memories enabled is on. With it off, expect each allowed MCP's tools, prefixed with the MCP's name. -
Ask the client to list available connectors. MCPs under Connection needed still need a one-time connect.
If sign-in succeeds but calls are refused, check that the client is allowed under Allowed Agents and that you can reach the MCP under access control.
Agent Configuration
- Each AI agent (OpenAI, Claude, Cursor, etc.) connects to the Quilr gateway URL shown on the server card, or to OneMCP
- The gateway identifies agents by their User-Agent header keyword
- Choose which MCPs each agent can reach with Allowed Agents on the MCP Gateway page (see Agents Configuration), or per server in Settings > General > Access control (see Access Control)