String API
MCP Server

Remote (hosted) MCP

Search the web, fetch any URL and map a site — the recommended hosted MCP server. Sign in, or bring an API key. Nothing to install.

The hosted MCP server runs at mcp.usestring.ai over Streamable HTTP, and is the recommended way to connect. Nothing to install, and you are always on the current tool set.

Works with the agent you already use

Any MCP client that supports remote Streamable HTTP servers works with String. These are the ones people reach for most.

  • and more

There is one endpoint and two ways to authenticate against it:

https://mcp.usestring.ai/v1/mcp

Sign in with String if your client supports it — Claude, ChatGPT, and OpenCode do. You add the URL, a browser window opens, you pick which of your Web Access keys the app should use, and that is it. No key is ever pasted into the app.

Present an API key for everything else. The key is forwarded to the API per request; there is no shared server key.

Sign in with String (OAuth)

Clients that support remote MCP connectors — Claude (web, desktop, mobile), Claude Code, and ChatGPT — can authenticate without handling your key at all.

Add the connector

In your client's connector settings, add a custom connector pointing at:

https://mcp.usestring.ai/v1/mcp

Sign in

A browser window opens on String. If you are not already signed in, you sign in as normal.

Choose the key it may use

The consent screen asks to grant web_access, and opens on Create a new key for this app, named for you and the app — SAM_CLAUDE_CODE_MCP_KEY, say. Edit the name, decide whether the key may solve captchas, and click Allow: the key is created for your organization and bound to this app in one step. Its value is never shown, here or later, because the connection spends it through that binding — there is nothing to paste anywhere.

To spend a key you already hold instead, pick it under Or use an existing key; the list shows each key's name and whether it solves captchas. An app you have connected before opens on the key it is already bound to, so re-consenting does not rotate it.

Nothing is created or saved until you click Allow — filling the form in and then denying leaves your organization's keys and this connection unchanged.

The app is connected. Requests it makes use the key you chose and bill your organization, exactly as if you had pasted that key in.

One key per app

Each connected app is bound to one specific key, so you can give a client a captcha-solving key and another a plain one, and tell their spend apart. Reconnecting the same app replaces its choice rather than adding a second one.

Managing connected apps

Every app your organization has connected is listed under Connected apps in settings, beside your API keys — the client, the key it uses, who connected it, and when it was last used. Connections are visible to your whole organization, because the key they spend belongs to the organization rather than to one person.

Disconnect removes the app's access to the key within a minute. The app stays signed in to String, so reconnecting takes one step, and your key itself is unchanged — other apps using it keep working.

Revoking a key disconnects its apps

Revoking a Web Access key immediately breaks every app connected with it. The revoke confirmation tells you how many apps that is. To move an app to a different key, reconnect it and pick the new key.

Present an API key

For clients without OAuth support, authenticate with your key directly. Both forms reach the same endpoint.

Send Authorization: Bearer YOUR_API_KEY to /v1/mcp. Use this with clients that support custom headers on a remote MCP server.

https://mcp.usestring.ai/v1/mcp
Authorization: Bearer YOUR_API_KEY

Put the key in the path — /<key>/v1/mcp — for clients that can only configure a URL. The server lifts the leading path segment into the bearer header.

https://mcp.usestring.ai/YOUR_API_KEY/v1/mcp

Both forms are supported alongside sign-in.

Client configuration

Clients with native remote/HTTP MCP support can use the URL directly. For clients that only speak stdio, bridge to the remote endpoint with mcp-remote:

mcpServers
{
  "mcpServers": {
    "string-ai": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://mcp.usestring.ai/YOUR_API_KEY/v1/mcp"]
    }
  }
}

OpenCode

OpenCode v2 can add the hosted server globally and complete String's OAuth flow without putting an API key in a project configuration:

opencode mcp add string-web-access --url https://mcp.usestring.ai/v1/mcp --global
opencode mcp auth string-web-access

The second command opens String's consent screen. Choose or create the key OpenCode may use; OpenCode stores the OAuth credentials outside project configuration. web_access_search and web_access_fetch are then available in every project.

Run opencode mcp list to check the connection. If it shows needs authentication, reconnect:

opencode mcp logout string-web-access
opencode mcp auth string-web-access

Kiro

Kiro takes a one-click install link. This one carries the endpoint and the bearer header already, and reads the key from a STRING_API_KEY environment variable — set that, or open Kiro's MCP settings after installing and paste the key into the header directly.

To do it by hand instead, add this to ~/.kiro/settings/mcp.json:

~/.kiro/settings/mcp.json
{
  "mcpServers": {
    "string-web-access": {
      "url": "https://mcp.usestring.ai/v1/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" },
      "disabled": false,
      "autoApprove": []
    }
  }
}

Zed

Zed supports remote MCP servers natively. Open Settings → AI → MCP Servers, choose Add Server, then Add Remote Server. Or put it in settings.json directly:

settings.json
{
  "context_servers": {
    "string-web-access": {
      "url": "https://mcp.usestring.ai/v1/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" }
    }
  }
}

Zed's MCP extensions only wrap servers that ship as a binary or an npm package, so the remote endpoint is added this way rather than by installing an extension.

goose

Run goose configure, choose Add Extension, then Remote Extension (Streamable HTTP), and give it the endpoint above with an Authorization header of Bearer YOUR_API_KEY. In the desktop app the same thing lives under Extensions → Add custom extension.

Muse Code

Muse Code reads MCP servers from ~/.config/muse/settings.json. Add this to its mcp_servers block — if the file already exists, put the entry inside the mcp_servers block it already has:

~/.config/muse/settings.json
{
  "schema_version": 1,
  "mcp_servers": {
    "string-web-access": {
      "transport": "streamable_http",
      "url": "https://mcp.usestring.ai/v1/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" },
      "mode": "optional"
    }
  }
}

Keep "schema_version": 1 in the file: without it, every muse command fails with malformed settings file. "mode": "optional" lets a run carry on with a warning if the server is unreachable, where Muse Code's default, required, aborts the whole run. Muse Code expands ${VAR} in server configs, so "Bearer ${STRING_API_KEY}" keeps the key itself out of the file. Muse Code connects with an API key, as above.

SSE endpoints (/sse and /<key>/sse) are not supported. Use https://mcp.usestring.ai/v1/mcp, or https://mcp.usestring.ai/YOUR_API_KEY/v1/mcp if your client can only configure a URL.

If your client cannot reach a remote MCP server, the same server can run locally over stdio.