Connect through browser sign-in
Use OAuth when the hosted settings offer Connect an AI agent and your client supports browser authentication. An Admin selects an eligible account and approves its scopes.
- Copy the MCP endpoint from Settings > MCP.
- Add a Streamable HTTP server named
pingstackto your client. - Leave manual Authorization headers empty.
- Start/reload the connection, then follow the browser sign-in.
- Select the intended account, review permissions and approve.
- Return to the client and request account capabilities to verify the binding.
The client refreshes access within the approved connection lifetime, up to 90 days. In Pingstack settings, inspect connected apps, approving user, expiry, permissions and last use. Disconnect immediately revokes the connection and its tokens.
Default requested scopes exclude sensitive heartbeat-URL access. Review requested permissions rather than assuming all tools are read-only. Browser authorization does not bypass account role checks.
Client examples
Section titled “Client examples”For Copilot, merge a header-free entry into private user config:
{ "mcpServers": { "pingstack": { "type": "http", "url": "https://pingstack.io/mcp", "tools": ["*"] } }}For Claude Code:
claude mcp add --transport http pingstack https://pingstack.io/mcpUse /mcp inside Claude Code and authenticate the connection. Refer to the
official Claude Code instructions
for current client controls.
Pingstack exposes OAuth resource/authorization-server discovery and uses browser authorization with PKCE. Let a compatible client handle discovery and token lifecycle; do not send an MCP OAuth access token to the REST API.
If OAuth is not offered or supported, follow manual-token setup rather than adding a made-up client secret.