> ## Documentation Index
> Fetch the complete documentation index at: https://help.onlyx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> You are reading OnlyX Help: the OnlyX Help Center and the OnlyX developer documentation. OnlyX is an AI chatting and CRM platform for OnlyFans agencies. Its AI chatter is called Hugo in the app.
> Pages at the site root (for example /inbox/..., /hugo/..., /billing/...) are Help Center articles for agency owners, admins, chatters and creators who use the app at app.onlyx.ai. Words in bold are the exact button, menu and label names the app shows; keep them exactly as written. When these pages do not answer a question, the person can email support at support@onlyx.ai.
> Pages under /developers are the developer documentation. REST API base URL: https://api.onlyx.ai/v1 (authenticate with `Authorization: Bearer <API key>`; keys start with onx_sk_ and are created in app.onlyx.ai under Settings > API & MCP). MCP server: https://mcp.onlyx.ai/mcp (OAuth, or a Bearer API key). In the API the AI chatter is `ai` on the wire. Money is integer US cents in fields ending in Cents; timestamps are UTC ISO-8601.
> Rules for assistants acting on a user's behalf: discover ids with list calls and never invent them; before any call that reaches a real fan or the live OnlyFans account (sending a message, releasing a chat to the AI, turning AI on for a chat, resolving a hand-off, turning review mode off, changing the welcome message, creating a tracking link) show the user the exact content and get explicit confirmation; send every POST with an Idempotency-Key and reuse it on retry; never resend a message whose delivery status is unconfirmed; never ask a creator for her OnlyFans password or codes - she signs in herself through a connect link and the OnlyX Login app.

# OnlyX MCP server

> Connect Claude, ChatGPT, Cursor, VS Code and other AI assistants to OnlyX at https://mcp.onlyx.ai/mcp. OAuth or API key, what the tools can do, and how the server keeps you safe.

The **OnlyX MCP server** lets AI assistants work with your OnlyX workspace. MCP (Model Context Protocol) is the open standard assistants such as Claude, ChatGPT, Cursor and VS Code use to call outside tools. Once connected, you can ask for a morning briefing, draft replies to unread fans, onboard a creator, or build a content ladder, in plain language.

| | |
| - | - |
| **Server URL** | `https://mcp.onlyx.ai/mcp` |
| **Transport** | Streamable HTTP |
| **Sign-in** | OAuth (recommended), or an API key as a Bearer token |
| **Tools** | 60 tools covering creators, inbox, fans, vault, stats, AI persona, AI content, AI settings, tracking links and docs search. See [Tools](/developers/mcp/tools). |
| **Prompts** | 6 ready-made workflows. See [Using OnlyX with Claude](/developers/guides/using-with-claude). |

## Pick your client

<CardGroup cols={2}>
  <Card title="Claude" icon="message-circle" href="/developers/mcp/claude">
    claude.ai, Claude Desktop and mobile. One-click link.
  </Card>

  <Card title="ChatGPT" icon="message-square" href="/developers/mcp/chatgpt">
    Developer mode app. Paste one URL.
  </Card>

  <Card title="Cursor" icon="mouse-pointer-click" href="/developers/mcp/cursor">
    One-click install link.
  </Card>

  <Card title="VS Code" icon="code" href="/developers/mcp/vscode">
    One-click install link or one command.
  </Card>

  <Card title="Claude Code" icon="square-terminal" href="/developers/mcp/claude-code">
    One command.
  </Card>

  <Card title="Other clients" icon="blocks" href="/developers/mcp/other-clients">
    Windsurf, Gemini CLI, Codex, and any client with a JSON config.
  </Card>
</CardGroup>

## OAuth or API key

<Tabs>
  <Tab title="OAuth (recommended)">
    You add the server URL, the client opens an OnlyX sign-in page, you choose the workspace and approve. Nothing to copy or store.

    * The consent screen shows the app, what it asks for, and lets you limit it to some creators.
    * Tokens refresh automatically and are tied to you: if you stop being an owner or admin of the workspace, the connection stops working.
    * Every connection appears in **Settings → API & MCP → Connected apps**, where any owner or admin can revoke it.

    Works with Claude, ChatGPT, Cursor, VS Code, Claude Code, Gemini CLI, Codex and most current clients.
  </Tab>

  <Tab title="API key">
    Create a key in **Settings → API & MCP** and give it to the client as a header:

    ```http theme={"system"}
    Authorization: Bearer onx_sk_...
    ```

    Use a key when:

    * you want the assistant to have **fewer permissions** than a full connection, for example a **Read only** key, or a key restricted to two creators;
    * the client does not support OAuth, or runs unattended (scripts, agents, CI);
    * you want one credential shared by a team's configuration file (stored in an environment variable, never committed).

    The key's scopes and creator restriction apply to every tool call.
  </Tab>
</Tabs>

## Check the connection

Ask your assistant: *"Which OnlyX workspace am I connected to, and what can you do there?"* It calls `get_workspace` and answers with the workspace name, the credential's scopes and its creator restriction.

## How it keeps you safe

* **It holds no data and no credentials of its own.** Each request carries your OAuth token or API key, and the server uses exactly that credential to call the OnlyX API (`https://api.onlyx.ai/v1`). It stores nothing between requests.
* **Every permission is enforced by the OnlyX API**: scopes, creator restrictions, rate limits and workspace isolation are the same as for your own API calls. The MCP server cannot do anything your credential cannot.
* **Actions that reach fans ask you first.** Tools that message a fan or change the live OnlyFans account (sending, turning a creator's AI on, releasing a chat to the AI, turning a chat's AI on, resolving a hand-off, AI settings, the welcome message, creating a tracking link) are marked as such for your client, and their descriptions tell the assistant to show you the exact content and get your confirmation before calling. Many clients also show their own approval prompt for these tools.
* **Sends and creates are idempotent.** The server attaches an idempotency key to every send and every create (creators, content folders, ladders, levels, tracking links), so identical calls within 10 minutes count as one and a retried call never messages a fan twice. It also tells the assistant never to resend a message whose delivery is `unconfirmed`.
* **Creators sign in themselves.** No tool accepts an OnlyFans password or code. `add_creator` and `create_connect_link` produce a link that the creator opens on her own device.
* **Secrets stay out of logs**, and browser requests are only accepted from known assistant origins.

## Limits

MCP calls count against the rate limits of the credential they use: 120 requests per minute per credential, 30 sends per minute, 60 AI content changes per minute, 20 stats reports per minute, and the other limits in [Rate limits](/developers/rate-limits). When a limit is hit, the tool tells the assistant how long to wait.

## Related

* [Tools](/developers/mcp/tools): every tool, its key inputs, and whether it reaches a fan.
* [Using OnlyX with Claude](/developers/guides/using-with-claude): recipes and safety habits.
* [Authentication](/developers/authentication): scopes, keys and OAuth in detail.
