One MCP URL for all your connectors.
Connect your accounts once. claude.ai, Claude Code, Cursor — every agent reaches them through a single OAuth-protected endpoint, with scoped writes, enforced constraints, and a full audit trail.
https://app.gentkey.com/mcpclaude.ai (web & mobile) · Claude Code · Cursor · any MCP clientProviders hand your agent a key to the whole house.
Gentkey cuts it a key to one room.
Four moving parts. One contract.
Connect your accounts
Google Ads over OAuth, Stripe with a restricted key, or any remote MCP server by URL. Credentials are encrypted at rest and never leave the server.
Hand every agent one URL
Each client completes a standard OAuth flow and lands in its own Gentkey — your connections, nobody else’s. No per-tool API keys to scatter around.
The policy gate decides
Read tools work out of the box and can be switched off. Write tools require an explicit grant, bounded by constraints like max $ delta/day = 50.
Every decision is recorded
Allowed, denied, or denied by constraint — each call lands in the audit log with the agent, tool, and reason. Filter it live, per connection or per agent.
Same grant, same tool,
different outcome.
google-ads.write.budget · max $ delta/day = 50›Raise the Summer Sale campaign budget by $30.
google_ads.update_budgetallowed+$30.00 is within the daily cap. Executed upstream, recorded in the log.
›Great — now raise it by $500.
google_ads.update_budgetdenied by policyΔ$500.00 exceeds the $50/day constraint. Nothing changed upstream — and the denial is in the log too.
The agent keeps its autonomy. You keep the blast radius.
Custody, gating, and audit — built in.
Writes need a grant
Reads work out of the box. Anything that changes state needs a capability you granted explicitly — revoke it and the next call is denied.
Constraints are enforced, not suggested
Grants carry hard bounds — max budget delta per day, max refund per call. The policy gate does arithmetic, not vibes.
The model never sees a credential
Tokens and keys are encrypted at rest and injected server-side at call time. Nothing secret ever enters the context window.
A trail you can act on
Every decision is attributed to the agent that made it. See what each agent called and searched for — and revoke its tokens in one click.
Any remote MCP server
Proxy Notion, Linear, Sentry, GitHub — or any URL. Upstream tools default to write-gated; vendor self-labeling isn’t trusted.
A catalog that doesn’t eat context
Past 20 tools, agents get three meta-tools (~350 tokens) and search the catalog instead of loading every schema up front.
Native connectors, plus any MCP server.
Google Ads and Stripe get deep, semantic constraints. Everything else gets custody, gating, and audit the day its vendor ships an MCP server.
Cut smaller keys.
Sign in, connect an account, and grant your first scoped capability in under a minute.