CursorAI-powered code editor
OAuth
ClaudeOfficial connector for Claude.ai, Desktop & mobile
OAuth
Claude custom connector
- Open Claude Connectors settings
- Add a custom connector with this server URL and complete the Wiv Air OAuth sign-in
Claude Desktop
- Open Settings → Connectors
- Click “Add connector” and paste the server URL
- Complete the OAuth sign-in when prompted
Claude.ai
- Go to Settings → Connectors → Add custom connector
- Paste the server URL and complete the sign-in
VS CodeVisual Studio Code with Copilot
OAuth
ChatGPTOpenAI ChatGPT with MCP
OAuth
- Open Settings → Connected apps
- Click “Add MCP server”
- Paste the server URL and complete the sign-in flow
Gemini CLIGoogle Gemini command line
OAuth
Add to your settings.json:
WindsurfCodeium Windsurf editor
OAuth
Amazon Quick & API key clientsHeader-based auth when OAuth is unavailable
API key
Prefer User authentication (OAuth) in Amazon Quick when discovery works. If your client only supports custom headers:
- Create a Wiv organization API key in the Wiv app (Avatar → API Keys).
- Add a remote MCP server with URL
. - Add header
x-api-keywith your API key value (use the secret/locked field when available). - Test the connection — invalid keys are rejected with
401 Unauthorized.
Docs: API key authentication
Before you connect
Prerequisites. You need an active Wiv organization account with Wiv Air enabled (apps.air). Your org admin can grant Air access if you do not have it yet.
What you are granting. When you sign in with OAuth, this MCP server receives an authorization from Wiv (via PropelAuth). The server exchanges that for a short-lived context and creates or uses an organization API key so tools can call the Air API on your behalf—read-only monitoring of spend, utilization, users, and connector health within your data scope.
OAuth flow (summary).
- You add the MCP URL (shown above) in your AI client and start the connection.
- Your browser opens Wiv sign-in (PropelAuth).
- After success, the client receives credentials to call this server; the server forwards requests to
air-api.wiv.ai(or the configured API base) with your API key.
API key alternative. Clients that cannot complete OAuth may send an Air organization API key as X-API-Key. Prefer OAuth when your client supports it.
Revoking access. Remove the connector in your AI client settings, or rotate/revoke API keys from your organization settings.
About this connector
Wiv Air is AI developer-tool spend visibility and governance. This remote MCP server exposes read-only Air monitoring APIs through the Model Context Protocol.
It is separate from the main Wiv platform MCP at mcp.wiv.ai (workflows/cases). Docs: docs.wiv.ai/air/platform/mcp-server.
Transports. Streamable HTTP at /mcp (recommended) and SSE at /sse (deprecated). OAuth scopes: mcp:tools, mcp:resources.
MVP capabilities. 12 read-only tools covering overview, usage, Cost Explorer, per-user spend, cap utilization, identities, and connector health. Money is in cents; cost_basis defaults to list.
Available tools
12 tools — all READ (read-only / idempotent).
Overview & usage
air_get_overviewOrg KPIs / spend / forecastair_get_usage_summaryUsage rollups by user/model/groupair_get_utilizationCursor seat utilizationCost Explorer
air_get_cost_explorer_usageGrouped spend/tokensair_get_cost_explorer_optionsFilter typeahead valuesUsers & caps
air_list_users_spendPaged users with limits & spendair_get_user_consumptionOne user's cycle spendair_get_user_model_usagePer-model breakdownair_get_user_daily_costDaily cost seriesair_get_cap_utilizationNear/over cap usersair_list_identitiesPeople directoryConnectors
air_get_connectors_healthSync freshness / healthResources
air://guides/monitoring-reference — units, cost basis, freshness, scope, paging and error semantics.
Prompts
Quick-start prompts for monitoring tasks.
air_spend_overviewSummarize org AI spend and connector healthair_top_spendersFind top spenders for a billing periodPrivacy & security
This page is served over HTTPS. For directory and compliance, link to this section as:
What we collect
- Authentication data: OAuth authorization codes and tokens during sign-in; temporary mapping between tokens and Air API keys in server memory.
- Account context: Organization identifiers and user identifiers as returned by PropelAuth / WIV when you sign in, to scope API keys and requests.
- Tool usage: Requests your AI client sends to this MCP server (tool names and parameters) are forwarded to the Air API; they are not stored by this MCP service for analytics.
How we use it
- To authenticate you and authorize calls to the Air API on your behalf.
- To maintain your MCP session while connected (including short-lived caching of resolved credentials to reduce repeated token exchange).
Storage & retention
- In-process caches (e.g. token-to-key mapping) are bounded and time-limited (on the order of one hour unless configured otherwise).
- Authorization codes used in the OAuth code flow expire within minutes.
- Long-lived API keys are issued and revoked through Wiv / PropelAuth; this server does not define separate retention beyond what your identity provider stores.
Third parties
- PropelAuth — authentication, OAuth, and API key management for WIV.
- Air API — source of truth for Air spend, utilization, and tenant monitoring data.
- AWS — hosting (e.g. App Runner) for this MCP service.
Security measures
- TLS (HTTPS) for client-to-server traffic.
- OAuth 2.0 with PKCE for compatible clients; optional API key header for trusted configurations.
- Token introspection for opaque tokens before issuing Air API keys.
Your choices
- Disconnect the connector in your AI product settings at any time.
- Use org and identity settings in Wiv / PropelAuth to manage users, roles, and API keys.
Contact
Questions about this connector or your data: support@wiv.ai · wiv.ai