Skip to content

Coding tools

MCP server

Let Claude Code and Codex check your credit and manage their own API keys.

Connect Deference's MCP server once, and your agent creates its own capped API keys, rotates and revokes them, and checks your credit and usage. Adding credit stays with you.

Connect Claude Code

  1. Add the server for every project.
claude mcp add --transport http --scope user deference https://deference.si/api/mcp
  1. In Claude Code, run /mcp, pick deference and choose Authenticate. Your browser opens on Deference. Sign in if asked, then select Allow. From a shell, claude mcp login deference does the same.

--scope user makes the server available in every project, because your credit belongs to your account, not to a repository.

Connect Codex

  1. Add the server.
codex mcp add deference --url https://deference.si/api/mcp
  1. Codex sees that the server needs a sign-in and opens your browser. Select Allow on Deference. If the browser does not open, run codex mcp login deference.

The command writes this to ~/.codex/config.toml:

[mcp_servers.deference]
url = "https://deference.si/api/mcp"

Connect another client

Any client that supports remote MCP servers with OAuth can connect, including Cursor and VS Code. Use this URL.

https://deference.si/api/mcp

Sign in

The consent page names the app, says whether Deference recognizes it, and lists what it can do. Allow it only if you just started the connection yourself.

You sign in once. After that the agent refreshes its own access, including in headless runs such as claude -p or CI on the same machine. A connection unused for 30 days asks you to sign in again, and so does every connection after 90 days.

What your agent can do

Every connection can read:

  • deference_get_balance shows your credit and free credit.
  • deference_list_keys lists your API keys, masked, with limits, spend and expiry.
  • deference_get_key_status shows one key's status, spend and what it has left.
  • deference_get_usage sums spend, requests and tokens over 24 hours to 90 days, for the account or one key.
  • deference_list_models lists model ids and prices, with search and paging.
  • deference_get_model shows one model's details and prices.

A connection you allow to manage keys can also:

  • deference_create_key creates a capped, expiring key, returns it once, and adds setup for Claude Code, Codex and OpenAI-compatible clients.
  • deference_rotate_key replaces a key it created with a new secret. The old key stops at once.
  • deference_revoke_key turns off a key it created.

A typical run: the agent checks your balance, creates a key, stores it in DEFERENCE_API_KEY, does its work on /v1, checks what it spent, and revokes the key when it finishes.

Prices come back in USD per million tokens, per request or per input image: OpenRouter's price plus OpenRouter's 5% platform fee. Deference adds no markup.

Limits on agent keys

A key an agent creates has a spend limit of $10 unless it asks for another, never more than $100, and expires after 30 days unless it asks for 7 or 90. Together, the keys agents create on your account can add at most $100 of spend limits in any 24 hours, even if they revoke and recreate keys. An account can have 10 active agent keys, and agents can make 20 key changes an hour. An app can rotate or turn off only the keys it created.

Agent keys are named after what the agent asked for, then the app, for example ci · Claude Code. Raise a key's limit or remove it on API keys.

Rotate keys from shared transcripts

A new key appears in the agent's conversation. If you share or store that transcript, rotate the key.

What stays with you

An agent cannot buy or activate INFERENCE, claim rewards or move funds. When credit runs low, it asks you to add credit. Changing a key's limit, deleting keys and managing connected apps also stay in the dashboard.

Disconnect

Open Settings, find the app under Connected apps and select Disconnect. The app loses access at its next request, and you can turn off the keys it created in the same step.

Then remove the server from the client.

claude mcp remove deference

To sign the client out but keep the server listed, run claude mcp logout deference or codex mcp logout deference.

Troubleshooting

You seeCauseFix
/mcp shows Needs authenticationThe client has not signed in yet, or its sign-in endedChoose Authenticate
invalid_grant after a long breakThe sign-in went unused for 30 days, or is 90 days oldSign in again
A tool says This connection can only readThe app was allowed to read onlyReconnect and allow key changes
Too many key changesMore than 20 creates, rotations and revocations in an hourWait the minutes it names