Skip to content

Sign in with Muro (OAuth)

claude.ai and ChatGPT connectors cannot send an Authorization header, so they cannot use an API key. For them the server has a second address that signs you in with your Muro account:

https://mcp.usemuro.com/account/mcp

It exposes the same eight tools as /mcp. Painting spends the credits of the account you sign in with.

  1. In your assistant, add a custom connector with the URL above. In claude.ai: Settings → Connectors → Add custom connector, authentication left empty. In ChatGPT: Settings → Apps & Connectors → Advanced → Developer mode → Create, with OAuth.
  2. A Muro page asks “Connect assistant name to your Muro account?”. It says who published the app and where access goes, and lists what the assistant may do:
    • paint your room photos in the colours you ask for, using your Muro credits
    • see your credit balance
  3. Continue to Muro takes you to app.usemuro.com. Sign in if you are not signed in, and confirm again.
  4. You are sent back to the assistant, now connected. Cancel at either step connects nothing.

If the page says the link expired or was already used, go back to the assistant and start connecting again.

Connecting creates an API key for that assistant. It is listed in app.usemuro.com → Settings → API keys under the assistant’s name.

Revoke that key in Settings → API keys. The next call from the assistant is rejected (“key rejected”), and you can remove the connector in the assistant too.

The Worker at mcp.usemuro.com is the OAuth 2.1 authorization server, built on @cloudflare/workers-oauth-provider. The client never holds your Muro key, only a token issued by this Worker.

  1. The client calls /account/mcp, gets a 401, discovers the authorization server from the resource metadata, and registers itself at /register (or presents a Client ID Metadata Document).
  2. /authorize shows the consent page. Continue hands the browser to app.usemuro.com/connect, with state, client and client_name.
  3. The Muro app signs you in, asks again, creates a muro_sk_… key for that client, and POSTs state and key (or error) as a form to /oauth/callback. The key never appears in a URL.
  4. The callback checks the browser-bound state and verifies the key against the Muro API. It stores the key encrypted inside the grant. The client receives an opaque token from /oauth/token.
Item Value
Resource https://mcp.usemuro.com/account/mcp
Scope muro
Registration /register, or Client ID Metadata Document
Authorization / token /authorize, /oauth/token

/account/mcp, /register, /authorize and /oauth/* share the keyed rate limit: 60 requests per 60 seconds per client IP. See Pricing and limits.

Clients that can send headers (Claude Code, Cursor, VS Code, scripts) should use an API key at /mcp instead. For the server’s discovery document see https://mcp.usemuro.com/.well-known/mcp.json.