Connect via MCP
Sandbox live. Create a free sandbox workspace at agentic-sandbox.pinkwallet.com (test credentials only; no money moves). Production is not yet available.
Pink Agentic AI Payments (by PinkWallet, early access) is the approval layer between AI agents and company money: plain-language rules, per-agent budgets and human approvals decide each payment before a one-time card or bank transfer is issued.
Endpoint: POST https://agentic-sandbox.pinkwallet.com/mcp (Streamable HTTP, stateless, JSON)
Auth A: Authorization: Bearer <agent_key> — header form
Auth B: POST https://agentic-sandbox.pinkwallet.com/mcp/<agent_key> — key in the URL path, no header
Both forms are served by the same Cloudflare Worker and were confirmed live on 2026-10-01 against a freshly created sandbox workspace: tools/list returns the same 7 tools (pink.get_budget, pink.list_payees, pink.list_rules, pink.check_policy, pink.request_payment, pink.get_credential, pink.report_receipt) over raw JSON-RPC and over the official MCP TypeScript SDK, through both auth forms.
The 14 clients
| Client | How | Auth form | Status |
|---|---|---|---|
| Claude Code | claude mcp add --transport http pink <url> [--header "Authorization: Bearer <key>"] | key in URL, or Bearer header | tested by us on 2026-10-01 |
| Claude.ai / Claude Desktop | Settings → Connectors → Add custom connector → paste URL | key in URL (no OAuth) | tested by the sandbox maintainers |
| Anthropic Messages API | mcp_servers:[{type:"url",url:...,authorization_token:...}] + beta header | Bearer | per the vendor docs + the sandbox maintainers |
| ChatGPT (Developer mode) | Settings → Connectors → Create → paste URL | key in URL | tested by the sandbox maintainers |
| OpenAI Responses API | tools:[{type:"mcp",server_url:...,headers:{Authorization:...}}] | Bearer | per the vendor docs + the sandbox maintainers |
| OpenAI Agents SDK (Python) | MCPServerStreamableHttp(params={"url":...,"headers":{...}}) | Bearer | per the vendor docs + the sandbox maintainers |
| Gemini CLI | gemini mcp add --transport http --header "Authorization: Bearer <key>" pink <url> or settings.json | Bearer | per the vendor docs |
| Cursor | .cursor/mcp.json → url + headers | Bearer | per the vendor docs |
| Windsurf | same shape as Cursor, Windsurf's own MCP config file | Bearer | per the vendor docs |
| VS Code (Copilot agent mode) | .vscode/mcp.json → type:"http", url, headers | Bearer | per the vendor docs |
| Microsoft Copilot Studio | Tools → Add a tool → Model Context Protocol → paste URL | key in URL | tested by the sandbox maintainers |
| LangChain / LangGraph | MultiServerMCPClient({"pink":{"transport":"http","url":...,"headers":{...}}}) | Bearer | per the vendor docs |
| CrewAI | MCPServerAdapter({"url":...,"transport":"streamable-http","headers":{...}}) | Bearer | per the vendor docs |
| n8n | MCP Client node → HTTP Streamable → Bearer Auth credential | Bearer | per the vendor docs |
Anything else (official MCP SDKs: TypeScript, Python, Java, Kotlin, C#, Swift, Go, Ruby, Rust; or plain REST /v1/*) | official SDK docs, or REST | either | tested by us on 2026-10-01 (TypeScript SDK only) |
Label key. Tested by us on 2026-10-01: we ran this exact flow against the live sandbox for this guide. Tested by the sandbox maintainers: PinkWallet's engineers tested this GUI flow against the live sandbox; we did not independently re-run it (GUI-only, can't be driven headlessly). Per the vendor docs: config shape copied from the client's own current documentation; not run against this sandbox in this pass.
Claude Code
Tested by us against the live sandbox: on 2026-09-30 claude mcp get pink reported Connected, and on 2026-10-01 both auth forms were added with claude mcp add. If you add the server at project scope (--scope project), Claude Code asks you to approve it the first time you run claude in that folder; until then claude mcp list shows it as pending approval.
# key in the URL path
claude mcp add --scope project --transport http pink \
"https://agentic-sandbox.pinkwallet.com/mcp/<agent_key>"
# or, Bearer header
claude mcp add --scope project --transport http pink \
"https://agentic-sandbox.pinkwallet.com/mcp" \
--header "Authorization: Bearer <agent_key>"
Claude.ai / Claude Desktop
Primary method — custom connector with the key in the URL, tested by the sandbox maintainers against the live host (no OAuth needed in this sandbox build):
- Settings → Connectors → Add custom connector.
- Paste
https://agentic-sandbox.pinkwallet.com/mcp/<agent_key>as the URL.
Alternative — if your client only accepts a bare URL with no path secret, or you're wiring this into a local config file instead of the GUI, use the mcp-remote bridge (documented at github.com/geelen/mcp-remote; not re-tested this pass):
{
"mcpServers": {
"pink": {
"command": "npx",
"args": ["mcp-remote", "https://agentic-sandbox.pinkwallet.com/mcp", "--header", "Authorization:${PINK_AUTH_HEADER}"],
"env": { "PINK_AUTH_HEADER": "Bearer <agent_key>" }
}
}
}
Anthropic Messages API
Per the vendor docs (docs.claude.com) and the sandbox maintainers' notes; not run in this pass (no Anthropic key budgeted for this task).
{
"mcp_servers": [
{ "type": "url", "url": "https://agentic-sandbox.pinkwallet.com/mcp", "name": "pink", "authorization_token": "<agent_key>" }
]
}
Requires the beta header mcp-client-2025-11-20 on the Messages API request.
ChatGPT (Developer mode)
Tested by the sandbox maintainers against the live host. Settings → Connectors → Create → paste https://agentic-sandbox.pinkwallet.com/mcp/<agent_key> as the URL (key in path; available on Plus/Pro/Business/Enterprise plans with Developer mode enabled).
OpenAI Responses API
Per the vendor docs + the sandbox maintainers; not run in this pass.
{
"tools": [
{ "type": "mcp", "server_label": "pink", "server_url": "https://agentic-sandbox.pinkwallet.com/mcp", "headers": { "Authorization": "Bearer <agent_key>" } }
]
}
OpenAI Agents SDK (Python)
Per the vendor docs + the sandbox maintainers; not run in this pass (would need the openai-agents package and an OpenAI key, out of this task's scope).
from agents.mcp import MCPServerStreamableHttp
pink = MCPServerStreamableHttp(
name="Pink",
params={"url": "https://agentic-sandbox.pinkwallet.com/mcp", "headers": {"Authorization": f"Bearer {agent_key}"}},
)
Gemini CLI
Per the vendor docs; not run in this pass. Config snippet parsed as valid JSON.
gemini mcp add --transport http --header "Authorization: Bearer <agent_key>" pink https://agentic-sandbox.pinkwallet.com/mcp
Or in settings.json:
{
"mcpServers": {
"pink": {
"httpUrl": "https://agentic-sandbox.pinkwallet.com/mcp",
"headers": { "Authorization": "Bearer <agent_key>" }
}
}
}
Cursor
Per the vendor docs (cursor.com/docs/context/mcp); not run in this pass (GUI app). Config snippet parsed as valid JSON.
{
"mcpServers": {
"pink": {
"url": "https://agentic-sandbox.pinkwallet.com/mcp",
"headers": { "Authorization": "Bearer ${env:PINK_AGENT_KEY}" }
}
}
}
Windsurf
Per the vendor docs; not run in this pass (GUI app). Windsurf uses the same url + headers MCP config shape as Cursor, in its own MCP config file. Snippet parsed as valid JSON.
{
"mcpServers": {
"pink": {
"url": "https://agentic-sandbox.pinkwallet.com/mcp",
"headers": { "Authorization": "Bearer <agent_key>" }
}
}
}
VS Code (GitHub Copilot agent mode)
Per the vendor docs (code.visualstudio.com/docs/agents/reference/mcp-configuration); not run in this pass (GUI app). Config snippet parsed as valid JSON.
{
"servers": {
"pink": { "type": "http", "url": "https://agentic-sandbox.pinkwallet.com/mcp", "headers": { "Authorization": "Bearer ${input:pink_agent_key}" } }
},
"inputs": [
{ "type": "promptString", "id": "pink_agent_key", "description": "Pink sandbox agent key", "password": true }
]
}
Microsoft Copilot Studio
Tested by the sandbox maintainers against the live host. Tools → Add a tool → Model Context Protocol → paste https://agentic-sandbox.pinkwallet.com/mcp/<agent_key> as the Streamable HTTP URL (key in path).
LangChain / LangGraph (langchain-mcp-adapters)
Per the vendor docs; not run in this pass.
from langchain_mcp_adapters.client import MultiServerMCPClient
client = MultiServerMCPClient({
"pink": {"transport": "http", "url": "https://agentic-sandbox.pinkwallet.com/mcp", "headers": {"Authorization": f"Bearer {agent_key}"}}
})
tools = await client.get_tools()
CrewAI
Per the vendor docs; not run in this pass.
from crewai_tools import MCPServerAdapter
pink = MCPServerAdapter({
"url": "https://agentic-sandbox.pinkwallet.com/mcp",
"transport": "streamable-http",
"headers": { "Authorization": f"Bearer {agent_key}" },
})
n8n
Per the vendor docs; not run in this pass. Add an MCP Client node, transport HTTP Streamable, URL https://agentic-sandbox.pinkwallet.com/mcp, and a Bearer Auth credential holding the agent key.
MCP TypeScript SDK (the reference client)
Tested live on 2026-10-01 — both auth forms, listTools() and one callTool({ name: "pink.check_policy", ... }) against the live sandbox. This is the same SDK the sandbox's own test suite uses.
import { Client } from '@modelcontextprotocol/sdk/client/index.js';
import { StreamableHTTPClientTransport } from '@modelcontextprotocol/sdk/client/streamableHttp.js';
// key in the URL path
const mcp = new Client({ name: 'my-agent', version: '0.0.1' });
await mcp.connect(new StreamableHTTPClientTransport(
new URL('https://agentic-sandbox.pinkwallet.com/mcp/<agent_key>')
));
// — or, Bearer header —
const mcp2 = new Client({ name: 'my-agent', version: '0.0.1' });
await mcp2.connect(new StreamableHTTPClientTransport(
new URL('https://agentic-sandbox.pinkwallet.com/mcp'),
{ requestInit: { headers: { Authorization: 'Bearer <agent_key>' } } }
));
const budget = JSON.parse((await mcp.callTool({ name: 'pink.get_budget', arguments: {} })).content[0].text);
Python mcp package
Attempted live on 2026-10-01: pip install mcp in a fresh venv failed — the package requires Python ≥3.10, and this environment's python3 is 3.9.10 (ERROR: Could not find a version that satisfies the requirement mcp). Per the vendor docs below (the package's own README pattern); use the curl or TypeScript samples above as the verified source of truth for this sandbox's actual behavior until you can test on a newer interpreter.
from mcp.client.streamable_http import streamablehttp_client
from mcp import ClientSession
async with streamablehttp_client("https://agentic-sandbox.pinkwallet.com/mcp/<agent_key>") as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
tools = await session.list_tools()
Anything else: official MCP SDKs or plain REST
Any official MCP SDK (Java, Kotlin, C#, Swift, Go, Ruby, Rust) speaks the same Streamable HTTP protocol with the same two auth forms; we only tested the TypeScript SDK directly (above). If you'd rather skip MCP entirely, every tool is also a plain REST endpoint — see Connect via REST.
Troubleshooting
- 401 Unauthorized — wrong, expired, or misspelled agent key. Confirmed live:
{"error":"unknown key"}with a bad key onPOST /mcp; an unauthenticatedGET /mcpalso 401s (www-authenticate: Bearer realm="pink-agentic-sandbox") because the auth check runs before the method check. - 405 Method Not Allowed — a
GET /mcprequest with a valid key. The server is stateless Streamable HTTP, POST-only (allow: POST, OPTIONS); there is no session to "get." - Keys are shown once — the full
admin_keyand per-agent keys are returned only in thePOST /v1/sandbox/workspacesresponse body and in the sandbox console at creation time. Save them; there's no "reveal key" endpoint afterward. - would_ask / pending_human on a payment you expected to be allowed — the sample templates include a night-time approval rule: between 23:00 and 06:00 workspace time, payments that would otherwise be allowed are sent for approval instead (rule r1, "Between 11pm and 6am: ask the owner", applies to every agent and every payee in the coffee template — confirmed in the sandbox's own template source). This is a business rule the template ships with, not a bug; run the call again during workspace business hours, or read the trace/reason field, which names the rule.
- Sandbox only, test credentials, no money moves. Production is not yet available.






