Connect to Wiv Air MCP

Query Wiv Air spend and utilization from your AI assistant. Add the server URL to your client and sign in when prompted.

Setup your client
Cursor
AI-powered code editor
OAuth
Open in Cursor

Or add manually to .cursor/mcp.json:


        
Claude
Official connector for Claude.ai, Desktop & mobile
OAuth
Connect Wiv Air in Claude

Claude custom connector

  1. Open Claude Connectors settings
  2. Add a custom connector with this server URL and complete the Wiv Air OAuth sign-in

Claude Desktop

  1. Open Settings → Connectors
  2. Click “Add connector” and paste the server URL
  3. Complete the OAuth sign-in when prompted

Claude.ai

  1. Go to Settings → Connectors → Add custom connector
  2. Paste the server URL and complete the sign-in

        
VS Code
Visual Studio Code with Copilot
OAuth
Open in VS Code

Or add to your settings.json under mcp.servers:


        
ChatGPT
OpenAI ChatGPT with MCP
OAuth
  1. Open Settings → Connected apps
  2. Click “Add MCP server”
  3. Paste the server URL and complete the sign-in flow
Gemini CLI
Google Gemini command line
OAuth

Add to your settings.json:


        
Windsurf
Codeium Windsurf editor
OAuth

        
AQ
Amazon Quick & API key clients
Header-based auth when OAuth is unavailable
API key

Prefer User authentication (OAuth) in Amazon Quick when discovery works. If your client only supports custom headers:

  1. Create a Wiv organization API key in the Wiv app (Avatar → API Keys).
  2. Add a remote MCP server with URL .
  3. Add header x-api-key with your API key value (use the secret/locked field when available).
  4. Test the connection — invalid keys are rejected with 401 Unauthorized.

Docs: API key authentication

Before you connect

Prerequisites. You need an active Wiv organization account with Wiv Air enabled (apps.air). Your org admin can grant Air access if you do not have it yet.

What you are granting. When you sign in with OAuth, this MCP server receives an authorization from Wiv (via PropelAuth). The server exchanges that for a short-lived context and creates or uses an organization API key so tools can call the Air API on your behalf—read-only monitoring of spend, utilization, users, and connector health within your data scope.

OAuth flow (summary).

  1. You add the MCP URL (shown above) in your AI client and start the connection.
  2. Your browser opens Wiv sign-in (PropelAuth).
  3. After success, the client receives credentials to call this server; the server forwards requests to air-api.wiv.ai (or the configured API base) with your API key.

API key alternative. Clients that cannot complete OAuth may send an Air organization API key as X-API-Key. Prefer OAuth when your client supports it.

Revoking access. Remove the connector in your AI client settings, or rotate/revoke API keys from your organization settings.

About this connector

Wiv Air is AI developer-tool spend visibility and governance. This remote MCP server exposes read-only Air monitoring APIs through the Model Context Protocol.

It is separate from the main Wiv platform MCP at mcp.wiv.ai (workflows/cases). Docs: docs.wiv.ai/air/platform/mcp-server.

Transports. Streamable HTTP at /mcp (recommended) and SSE at /sse (deprecated). OAuth scopes: mcp:tools, mcp:resources.

MVP capabilities. 12 read-only tools covering overview, usage, Cost Explorer, per-user spend, cap utilization, identities, and connector health. Money is in cents; cost_basis defaults to list.

Available tools

12 tools — all READ (read-only / idempotent).

Overview & usage
READair_get_overviewOrg KPIs / spend / forecast
READair_get_usage_summaryUsage rollups by user/model/group
READair_get_utilizationCursor seat utilization
Cost Explorer
READair_get_cost_explorer_usageGrouped spend/tokens
READair_get_cost_explorer_optionsFilter typeahead values
Users & caps
READair_list_users_spendPaged users with limits & spend
READair_get_user_consumptionOne user's cycle spend
READair_get_user_model_usagePer-model breakdown
READair_get_user_daily_costDaily cost series
READair_get_cap_utilizationNear/over cap users
READair_list_identitiesPeople directory
Connectors
READair_get_connectors_healthSync freshness / health

Resources

air://guides/monitoring-reference — units, cost basis, freshness, scope, paging and error semantics.

Prompts

Quick-start prompts for monitoring tasks.

air_spend_overviewSummarize org AI spend and connector health
air_top_spendersFind top spenders for a billing period

Privacy & security

This page is served over HTTPS. For directory and compliance, link to this section as:

What we collect

  • Authentication data: OAuth authorization codes and tokens during sign-in; temporary mapping between tokens and Air API keys in server memory.
  • Account context: Organization identifiers and user identifiers as returned by PropelAuth / WIV when you sign in, to scope API keys and requests.
  • Tool usage: Requests your AI client sends to this MCP server (tool names and parameters) are forwarded to the Air API; they are not stored by this MCP service for analytics.

How we use it

  • To authenticate you and authorize calls to the Air API on your behalf.
  • To maintain your MCP session while connected (including short-lived caching of resolved credentials to reduce repeated token exchange).

Storage & retention

  • In-process caches (e.g. token-to-key mapping) are bounded and time-limited (on the order of one hour unless configured otherwise).
  • Authorization codes used in the OAuth code flow expire within minutes.
  • Long-lived API keys are issued and revoked through Wiv / PropelAuth; this server does not define separate retention beyond what your identity provider stores.

Third parties

  • PropelAuth — authentication, OAuth, and API key management for WIV.
  • Air API — source of truth for Air spend, utilization, and tenant monitoring data.
  • AWS — hosting (e.g. App Runner) for this MCP service.

Security measures

  • TLS (HTTPS) for client-to-server traffic.
  • OAuth 2.0 with PKCE for compatible clients; optional API key header for trusted configurations.
  • Token introspection for opaque tokens before issuing Air API keys.

Your choices

  • Disconnect the connector in your AI product settings at any time.
  • Use org and identity settings in Wiv / PropelAuth to manage users, roles, and API keys.

Contact

Questions about this connector or your data: support@wiv.ai · wiv.ai