Pick your client
Claude
claude.ai, Claude Desktop and mobile. One-click link.
ChatGPT
Developer mode app. Paste one URL.
Cursor
One-click install link.
VS Code
One-click install link or one command.
Claude Code
One command.
Other clients
Windsurf, Gemini CLI, Codex, and any client with a JSON config.
OAuth or API key
- OAuth (recommended)
- API key
You add the server URL, the client opens an OnlyX sign-in page, you choose the workspace and approve. Nothing to copy or store.
- The consent screen shows the app, what it asks for, and lets you limit it to some creators.
- Tokens refresh automatically and are tied to you: if you stop being an owner or admin of the workspace, the connection stops working.
- Every connection appears in Settings → API & MCP → Connected apps, where any owner or admin can revoke it.
Check the connection
Ask your assistant: “Which OnlyX workspace am I connected to, and what can you do there?” It callsget_workspace and answers with the workspace name, the credential’s scopes and its creator restriction.
How it keeps you safe
- It holds no data and no credentials of its own. Each request carries your OAuth token or API key, and the server uses exactly that credential to call the OnlyX API (
https://api.onlyx.ai/v1). It stores nothing between requests. - Every permission is enforced by the OnlyX API: scopes, creator restrictions, rate limits and workspace isolation are the same as for your own API calls. The MCP server cannot do anything your credential cannot.
- Actions that reach fans ask you first. Tools that message a fan or change the live OnlyFans account (sending, turning a creator’s AI on, releasing a chat to the AI, turning a chat’s AI on, resolving a hand-off, AI settings, the welcome message, creating a tracking link) are marked as such for your client, and their descriptions tell the assistant to show you the exact content and get your confirmation before calling. Many clients also show their own approval prompt for these tools.
- Sends and creates are idempotent. The server attaches an idempotency key to every send and every create (creators, content folders, ladders, levels, tracking links), so identical calls within 10 minutes count as one and a retried call never messages a fan twice. It also tells the assistant never to resend a message whose delivery is
unconfirmed. - Creators sign in themselves. No tool accepts an OnlyFans password or code.
add_creatorandcreate_connect_linkproduce a link that the creator opens on her own device. - Secrets stay out of logs, and browser requests are only accepted from known assistant origins.
Limits
MCP calls count against the rate limits of the credential they use: 120 requests per minute per credential, 30 sends per minute, 60 AI content changes per minute, 20 stats reports per minute, and the other limits in Rate limits. When a limit is hit, the tool tells the assistant how long to wait.Related
- Tools: every tool, its key inputs, and whether it reaches a fan.
- Using OnlyX with Claude: recipes and safety habits.
- Authentication: scopes, keys and OAuth in detail.