Skip to main content
Connect your agent once to give it search, research, enrichment, and other paid tools from your Locus catalog. Locus handles provider access and billing; you choose the tools and spending limits. Building with a model SDK? Go to Framework integrations. For direct API calls, use the Node SDK. See MCP for the tool reference and compact mode.

Connect an MCP client

The hosted MCP server uses Streamable HTTP:
MCP server URL
In your workspace, open Integrate → MCP clients. Add the MCP URL to your client and approve the connection in your browser. Locus Pro self-serve accounts use Connections. Choose the manual configuration below or the Locus plugin. You only need one connection.
Open Customize → Connectors → Yours → Add connector → Add custom connector. Name it Locus, enter the MCP server URL above, choose Connect, and complete browser sign-in.Then open Customize → Skills → Yours → Add skill → Upload skill and upload all three archives:This supplies the remote connector and complete skill tree to Claude surfaces that expose these account settings. Claude Code uses its plugin path below.

Install the Locus plugin

The Locus plugin bundles the OAuth connection with three skills: Locus for Tools and Recipes, Locus setup for onboarding, and Locus Workflows for building and running saved processes. Your client stores and refreshes the OAuth tokens.
Run /mcp, select locus, and choose Authenticate.
Use one OAuth entry per client. If you install the plugin after adding the server manually, remove the duplicate manual entry. For a service credential, use the manual configuration below. Other Agent Plugins clients can install the same bundle:
Install the plugin
Update through your client’s plugin manager, then start a fresh session. See the release notes; public marketplace listings may update separately from GitHub. For OpenClaw, Hermes, Muse, and Instinct, send this prompt in a new agent session:
The installer chooses a supported MCP or CLI adapter, installs locus, locus-setup, and locus-workflows, starts authentication, and checks a free readiness operation. Complete any browser approval or restart it requests.
Hermes does not currently have a public plugin listing. Current OpenClaw does not import the MCP entry from its marketplace bundle. Use the one-link route for both clients today.

Give your coding agent the Locus skills

Send your agent paywithlocus.com/SKILL.md, or install the skills when you are not using the plugin:
Install the skills
Select locus, locus-setup, and locus-workflows when prompted. A skills-only install still needs an authenticated MCP connection. Clients without local skill support can retrieve the same guides through MCP with get_locus_guide.

Enterprise service credentials

What an agent connection is

An Agent Connection gives one runtime access to a chosen balance and set of tools. You can set an expiry, a maximum charge per call, and a spending limit per run. Create it from API Keys → Service credentials or from your backend. Locus returns an lcac_… credential and ready-to-use MCP configuration.
Keep your lcr_… tenant secret key on your server. Give the agent a scoped lcac_… credential. Store credentials in a secret manager, never in prompts or source control.

Create a connection

Your server key needs both credentials:manage and credits:move to create or rotate a connection. Dashboard users must be an owner or admin and complete recent MFA or passkey verification.
1

Enable the tools

Enable the required endpoints in Agent tools. A connection can use only enabled workspace tools.
2

Create the credential

Create an Agent Connection
3

Save it securely

Store the returned credential immediately. It is shown only on creation and rotation.
End-user connections can also carry their own pricing overrides. See the API reference for the full creation contract.
Omitting tools allows all workspace-enabled endpoints. An empty tools.enable list permits none. Account and tool scope are fixed at creation; create a replacement to change them.

Enterprise service-credential configuration

Set LOCUS_AGENT_CONNECTION to the saved lcac_… credential.
Add to ~/.codex/config.toml:
~/.codex/config.toml
Hosted model APIs have their own authorization fields. Use the examples in Framework integrations.

Connection scope and budgets

To enforce a run budget, set maxCreditsPerLoop at creation. Give every paid call in that run the same ID: Concurrent calls share the same budget. Start a new ID only for a new run.

Use the MCP tools

Ask your agent to find the tool it needs, check the price, and use the result:
Send to your agent
MCP exposes discovery and execution tools without loading the entire catalog. See all MCP tools for the names and compact-mode equivalents. When using a quote, pass its unchanged approval_token, arguments, and idempotency_key to execute. Dedicated endpoint tools cannot consume an approval token.

Idempotency and replay

Reuse one idempotency_key when retrying a paid call. Locus returns the stored outcome without charging again. Use a new key for an intentional repeat, such as refreshing a search.

Turn structured results into final answers

Store the paid result before asking the model to summarize it. If answer generation fails, reuse that result instead of repeating the purchase. The SDK provides parseMcpToolResult to check tool errors, prepareMcpResultForSynthesis to build bounded context, and selectSynthesisAnswer for a fallback answer. The Locus skill covers the full runtime flow.

Rotate or revoke a connection

Manage connections in API Keys → Service credentials, or use the SDK:
Rotate or revoke
Rotation preserves scope. Revocation is immediate and permanent; a server key needs only credentials:manage to revoke a connection.

Troubleshoot a connection

Share the connection ID and error code with support. Never share the full credential.

Agent-owned headless OAuth

An agent-owned account signs in through AgentID. Keep the MCP login process alive while completing authorization so it retains its callback and PKCE state. Follow Agent-native onboarding and the AgentID authentication reference for the HTTP flow.

Headless device authorization (RFC 8628)

Clients without a redirect listener can register for the device-code grant. They display a verification link, wait for approval, and exchange the device code for tokens. The API reference documents registration, polling intervals, and token renewal.

Next steps