Connected agents
Every credential an agent holds - OAuth connections, paired agents, and manual keys. Revocable instantly, spend-capped by default ($1/call, $20/day, $200/month; edit any agent's daily cap below), never able to manage the account.
Connect an agent
One install, one approval - the agent authenticates itself and every call is quoted, validated, refunded on failure, and receipted under your caps. No key to paste.
Install (Claude Code)
claude mcp add --transport http nitrograph https://api.nitrograph.com/mcpThen run /mcp in Claude Code and pick Authenticate - the OAuth consent opens here and the agent holds tokens, never a pasted key.
Create a key manually
For scripts and CI that cannot do OAuth or pairing.
Guardrails: caps are enforced per key at charge time - a capped key can never outspend them.