Skip to main content

Call from your own code

This page is for developers who want a script, a backend service or an agent they run themselves to call NameBeta's tools, rather than an assistant such as Claude or Cursor.

Every token comes from a person signing in​

NameBeta has no API keys and no client credentials grant. Every access token the MCP server accepts was issued after a NameBeta user signed in in a browser and approved the client on the consent screen, as Authorization describes. A program that runs unattended cannot get its first token on its own: a person has to complete that sign-in once.

After that sign-in, the program can keep working without the person if it holds a refresh token: request offline_access together with prompt=consent, as described under Authorization request, and use the refresh token to get new access tokens as they expire.

No code sample yet

We have not yet run a script of our own through this flow end to end, so this page gives the steps and no code. Changelog will say when a tested example is added.

Routes that work today​

Use an agent that is already an MCP client​

If what you need is an agent with NameBeta's tools rather than your own client, run one of the clients we document, which handle sign-in and token refresh themselves. Claude Code and Codex run from a terminal and in scripts.

Write your own OAuth client​

To call the endpoint from your own code, your program acts as an OAuth client:

  1. Host a Client ID Metadata Document at an HTTPS URL you control. That URL is your client_id; the document lists your client's name and redirect URIs. Client registration explains why no other registration step exists. If you cannot host one, ask for a pre-registered client ID.
  2. Run the authorization code flow with PKCE once, in a browser, as the NameBeta user whose plan the calls should count against. Send resource=https://namebeta.com/api/mcp, and ask for offline_access with prompt=consent to get a refresh token.
  3. Store the refresh token where your program can read it, and exchange it for a new access token when the current one expires.
  4. Call the endpoint with Authorization: Bearer <access token>, one JSON-RPC request per POST, as Endpoint and transport describes.

The official MCP SDKs implement steps 2 and 4. The TypeScript SDK (@modelcontextprotocol/sdk, 1.30.0) uses a Client ID Metadata Document when the authorization server supports one and the client's OAuthClientProvider sets clientMetadataUrl; you still host the document yourself.

Pass a token to a model API​

The MCP connectors of model APIs call the server for you, but they do not sign in. You pass them an access token obtained as in the previous section, and refresh it yourself:

APIWhere the token goesVendor documentation
Claude API (Messages)authorization_token of the entry in mcp_serversMCP connector
OpenAI API (Responses)authorization of the mcp toolMCP and Connectors

Anthropic's documentation says: "API consumers are expected to handle the OAuth flow and obtain the access token prior to making the API call, and to refresh the token as needed." OpenAI's says: "OAuth client registration and authorization must be handled separately by your application."

What does not work​

  • A token copied out of another client. It was issued to that client and expires; build your own client instead.
  • Dynamic Client Registration. NameBeta does not offer it; see Client registration.