Security explained

Remote MCP server OAuth: why you press Allow, not paste keys.

When you connect an AI assistant to FoxEra Calls, the system opens a sign-in page and asks you to press Allow. No secret keys to copy, no config files to edit. Here is why that flow exists and what it actually does.

What is OAuth and why does it matter?

OAuth is the industry-standard way to let one service act on your behalf in another service without sharing your password. You have used it every time you pressed "Sign in with Google" on a website — the website never sees your Google password; Google confirms who you are and gives the website a limited pass.

The same principle applies when you connect an AI assistant to FoxEra Calls. Your assistant never sees your FoxEra password. Instead, it receives a token — a temporary pass that lets it call specific tools on your account. If you revoke the token, the pass stops working and your password stays unchanged.

How the sign-in flow works step by step

When you tell your AI assistant to connect to FoxEra Calls via the MCP server, the following happens:

  • Your assistant opens a sign-in page — this is hosted by FoxEra, not by the assistant. You log in with your own FoxEra credentials.
  • You see what the assistant is asking for — the consent screen lists the permissions (called scopes) the assistant will receive. For example: read leads, create campaigns, view transcripts.
  • You press Allow — FoxEra creates a token and sends it back to your assistant. The assistant stores the token and uses it for future requests.
  • Your assistant can now use the MCP tools — it can add leads, preview campaigns, read results and everything else the scopes permit.

At no point does your assistant see your password. The token it receives can be revoked at any time from your account settings.

OAuth versus pasting an API key

Some services ask you to copy a secret key from a settings page and paste it into your AI assistant's configuration. That works, but it has drawbacks:

  • A pasted key is a shared secret — anyone who sees the key can use your account. If you paste it into a chat window, it might be logged. If you save it in a file, the file might be read by something else.
  • OAuth tokens are scoped — they grant only the permissions you approved, not full access to your account.
  • OAuth tokens expire — they are refreshed automatically and can be revoked instantly. A pasted key stays valid until you manually delete it.

FoxEra supports both methods. The OAuth flow (press Allow) is the recommended default. If you need a long-lived key for a server-side integration, you can generate an fxk_ API key from your account settings — but for most users, OAuth is simpler and safer.

What scopes does FoxEra grant?

When you press Allow, the consent screen tells you exactly what your assistant can do. FoxEra's MCP server exposes tools for:

  • Reading account status — your balance, confirmed number and calling hours.
  • Managing leads — adding, listing and organising contacts into folders.
  • Running campaigns — creating, previewing, scheduling and approving campaigns. The approval step always requires your explicit confirmation.
  • Reading results — transcripts, recordings, outcomes and reports.
  • Editing scripts — reading and updating the calling pitch your AI agent follows.

Your assistant cannot change your password, delete your account or access billing details. The scope is limited to calling operations. For a full list of tools, see MCP phone calling tools explained.

Keeping your account safe

A few practical tips for staying in control:

  • Review connected services regularly — check your account settings for connectors you no longer use and revoke them.
  • Use OAuth over pasted keys — the flow is quicker, the token is scoped, and revoking is instant.
  • Change your password to disconnect everything — if you suspect someone else has access, changing your password invalidates all OAuth tokens at once.
  • Check scheduled campaigns after revoking — a campaign that was already approved will still run. Cancel it from the dashboard if needed.

FoxEra also requires a confirmed phone number and separate campaign approval before any calls are made, so even a connected assistant cannot dial without your say-so. Read more about pay-as-you-go AI calling and how billing works.

Frequently asked questions

Do I need to be a developer to connect via OAuth?

No. The process is a guided sign-in: your assistant opens a page, you log in and press Allow. No code, no config files, no API keys to paste.

What is the difference between an OAuth token and an fxk_ API key?

An OAuth token is created automatically when you press Allow, is scoped to the permissions you approved, and can be revoked from your account settings. An fxk_ API key is a long-lived key you generate manually for server-side integrations. Both work with the FoxEra API and MCP server.

Can my AI assistant change my password or delete my account?

No. The OAuth scope is limited to calling operations — managing leads, running campaigns and reading results. Account-level changes like password resets or deletion are not exposed through the MCP server.

Start free with £7 calling credit