Hosted clients use OAuth
Add only the MCP endpoint in a hosted connector. The client discovers the authorization service, opens sign-in and consent, then stores its own access token.
- No API key pasted into the URL
- Authorization code flow with PKCE
- Access can be revoked from Connected Apps