Skip to main content

Quick start

Add this URL to your MCP client and sign in with your Winston AI account:
No API key and no install are needed. The server uses the Streamable HTTP transport and OAuth 2.1. Credits are taken from your Winston AI account.

Connect your MCP client

Your client signs you in with OAuth 2.1 the first time you connect.

Claude

Go to Customize > Connectors, click +, then Add custom connector. Enter Winston AI as the name and https://api.gowinston.ai/mcp/v1 as the URL, then sign in.

ChatGPT

Turn on Developer mode in ChatGPT settings, then add a custom connector with the URL https://api.gowinston.ai/mcp/v1 and OAuth as the authentication. Custom connectors require a paid ChatGPT plan.

Claude Code

Cursor

Add to your mcp.json:

VS Code

Add to your .vscode/mcp.json:

Other MCP clients

Use the URL https://api.gowinston.ai/mcp/v1 with the Streamable HTTP transport. Any client that supports MCP authorization signs you in automatically.

Using an API key instead

You can also use a standard API key from our API platform by passing it in the Authorization header. Credits are then taken from your API platform account.

Tools

If you provide several inputs to ai-text-detection, website takes priority over file, and file takes priority over text.

Authentication

Every request must send a Bearer token in the Authorization header:
The token is either:
  • An OAuth 2.1 access token with the mcp:use scope. Your MCP client gets it for you when you sign in with your Winston AI account.
  • A standard API key from the API platform.
Never send the token in the request body or URL. Only the Authorization header is supported.

How the OAuth 2.1 flow works

MCP clients that support MCP authorization handle this for you:
  1. A request without a token receives 401 Unauthorized with a WWW-Authenticate header pointing to the protected resource metadata.
  2. The client reads https://api.gowinston.ai/.well-known/oauth-protected-resource, which lists https://app.gowinston.ai as the authorization server and mcp:use as the required scope.
  3. The client opens your browser so you can sign in to Winston AI and approve access.
  4. The client receives an access token and sends it as Authorization: Bearer <token> on every request.

Test with cURL

For quick tests with cURL, use a standard API key from the API platform. Replace your-winston-ai-api-key with it.

List tools

Call a tool

To call another tool, change name and arguments using the Tools table.

Troubleshooting

  • 401 Unauthorized: The token is missing, invalid, or expired. Sign in again from your MCP client, or check that the header is Authorization: Bearer <token>.
  • 403 Forbidden: The token doesn’t have the mcp:use scope. Disconnect and sign in again so your client requests it.
  • Out of credits: Top up your Winston AI account. If you use an API key, top up on the API platform.
  • Your client doesn’t support OAuth: Use an API key in the Authorization header. See Using an API key instead.

Self-hosting

To run the MCP server locally, see the Winston AI npm package.