Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.rheos.app/llms.txt

Use this file to discover all available pages before exploring further.

The Rheos MCP server lives at:
https://mcp.rheos.app
It supports two auth modes:
  • OAuth 2.1 — recommended for hosted clients (claude.ai, ChatGPT). The client redirects you to rheos.app, you approve, and a short-lived token is issued.
  • API key (Bearer) — recommended for local CLIs (Claude Code, Cursor, Windsurf). Generate one in Settings → MCP and paste it into the client config.
The OAuth flow uses the standard MCP discovery endpoint at https://mcp.rheos.app/.well-known/oauth-protected-resource. Clients that implement MCP authorization will pick this up automatically.

Generate an API key

1

Open MCP settings

2

Create a key

Click New API key, give it a label (e.g. “Cursor laptop”), and copy the secret. You’ll only see it once.
3

Store it safely

Treat the key like a password. Anyone with it can act as you in Rheos. Revoke unused keys from the same screen.

Client setup

Claude.ai uses OAuth — no API key needed.
1

Open Connectors

In claude.ai, click your avatar → SettingsConnectorsAdd custom connector.
2

Add Rheos

  • Name: Rheos
  • URL: https://mcp.rheos.app
Click Add.
3

Authorize

Claude.ai will redirect you to rheos.app to log in and approve. After approval you’ll be bounced back with the connection active.
4

Test

Start a new chat and ask: “What Rheos brands do I have?” Claude should call rheos_list_brands and return your brands.

Verifying the connection

Once connected, any of these prompts should produce a tool call:
  • “List my Rheos brands.”rheos_list_brands
  • “What’s my Rheos credit balance?”rheos_get_credits
  • “Show me the formula tree.”rheos_get_formulas
If the client returns “no tools available”, check:
  1. The Authorization header is exact — Bearer prefix included, no trailing whitespace.
  2. The key hasn’t been revoked. Re-check Settings → MCP in the dashboard.
  3. Your client supports the Streamable HTTP transport (most do as of 2026).
Never commit API keys to git. Use environment variables, a secret manager, or the client’s native credential store.

Rotating or revoking keys

Open Settings → MCP in the Rheos dashboard. Each key shows its last-used timestamp. Click Revoke to invalidate it immediately — any client using that key will start returning 401 within seconds. To rotate, generate a new key first, update your client config, then revoke the old one.
Last modified on May 15, 2026