Skip to main content
The Monei MCP server uses OAuth 2.1 with PKCE. You do not need to implement this yourself, your MCP client handles the OAuth flow automatically.

How it works

When you connect for the first time, your MCP client opens the Monei auth page at:
You enter your Monei API key. The server validates it against the Monei backend in real time before issuing any token. If the key is wrong, you see an error immediately on the auth page and nothing is stored. If the key is valid, an auth code is issued, exchanged for an access token, and stored by your MCP client. From that point, all tool calls are authenticated automatically.

Token lifetime

Access tokens expire after one hour. Your MCP client will re-run the OAuth flow automatically when the token expires. You will not need to re-enter your API key unless you disconnect and reconnect manually.

Using your local config

If you are running the server locally via npx or a global install, you can pass your API key directly as an environment variable instead of going through the OAuth flow:

Sandbox vs live

Your API key determines which environment you are in. A sandbox key hits api.dev.monei.cc and no real money moves. A live key hits api.monei.cc and transactions are real. Make sure you are using the right key for the right environment. See the Sandbox page for more detail.

Security

Your API key is validated at auth time and never stored in plain text by the MCP server. The server exchanges it for an opaque token that your MCP client holds. Do not share your API key or commit it to a public repository. If you suspect a key has been compromised, rotate it immediately in your Monei dashboard under Settings then API Keys.