# MCP quickstart

Three steps from zero to an agent reading the creator roster. Works with any client that speaks Streamable HTTP, and with plain REST.

## 1. Sign in through your client, or create an API key

Clients that support OAuth (Claude, ChatGPT, Claude Code, Cursor, Codex) only need the endpoint URL: add it and the client opens the AffiliateSpy sign-in page (sign up there if you are new) followed by a consent screen. Nothing to copy. For scripts, or clients that only take headers, create a key at https://www.affiliatespy.io/dashboard/settings?tab=api. Keys look like `asp_live_…` and can be revoked at any time.

## 2. Add the server to your client

The server is remote; nothing to install or run.

```
Endpoint  https://affiliatespy.io/api/mcp
Header    Authorization: Bearer asp_live_YOUR_KEY
```

Client-specific setup: https://www.affiliatespy.io/docs/claude, https://www.affiliatespy.io/docs/claude-code, https://www.affiliatespy.io/docs/cursor.

REST instead of MCP: `POST https://www.affiliatespy.io/api/v1/tools/{tool_name}` with the same bearer header and a JSON body of arguments. `GET https://www.affiliatespy.io/api/v1/tools` lists the tools with their argument schemas; the OpenAPI document is https://www.affiliatespy.io/openapi.json.

## 3. Ask your agent something

A good first prompt: "List my top-graded creators without an email revealed yet." The agent calls `list_apps` then `list_creators` and reasons over the result. Tool reference: https://www.affiliatespy.io/docs/tools.

## Limits and guarantees

- 60 requests per minute per API key.
- Endpoint: https://affiliatespy.io/api/mcp (stateless Streamable HTTP, 2025 and 2026 protocol revisions).
- Plan caps, the monthly reveal meter and contact sanitization are enforced server-side; the MCP and REST surfaces can never exceed what the dashboard allows.
- Guarded actions (launch, pause, resume, send, scan, autopilot changes) return approval_required with a summary and a token; the agent shows the summary, the user says yes, the agent calls again with the token. Accounts can skip approvals with Unrestricted MCP in Settings, API and agents.
- Before a plan: start_quick_scan, get_quick_scan_preview and get_checkout_link work; everything else returns no_subscription.
