ONE PLUG FOR AI AGENTS

One plug. Every app. Any agent.

Your users connect their apps once, under your brand. Your agent, or Claude, ChatGPT and Cursor, acts through one MCP endpoint, limited to what each user approved, with every action on the record.

MCP + REST  ·  Your brand on the consent screen  ·  Audit log on every plan
AGENTSAPPS
Claude
ChatGPT
Cursor
Your agent
ARC0
● LIVE
CONNECT
VAULT
POLICY
AUDIT
mcp.arc0.ai/u/u_8f2
Gmail
Slack
Salesforce
GitHub
Linear
Notion
AUDIT LOG · USER u_8f2 · CUSTOMER acme
gmail.send_email✓ allowed · 212ms
slack.post_message✓ allowed · 148ms
github.create_pull_request✓ allowed · 301ms
salesforce.delete_record✕ blocked
notion.search✓ allowed · 96ms
linear.create_issue✓ allowed · 174ms
WORKS WITH REMOTE-MCP CLIENTS AND AGENT FRAMEWORKS
ClaudeChatGPTCursorCodexVS CodeOpenAI Agents SDKClaude Agent SDKVercel AI SDKMastraLangGraph
01 · PRODUCTAPI PREVIEW

Everything between your agent and your users’ apps.

01+
Arc0 Connect

The flow your users authorize apps in, with your logo and colours. Your own domain and OAuth apps on paid plans.

connect.yourapp.com
02+
Vault

Credentials encrypted per tenant and refreshed before they expire. OAuth, API keys and basic auth.

GET /v1/connections/{id}/export
03+
Arc0 MCP

One endpoint per user. Point your own agent, Claude, ChatGPT or Cursor at it.

https://mcp.arc0.ai/u/{user}
04+
REST + proxy

The same connection from your backend, with no agent in the loop. One connection, two callers.

POST /v1/actions/gmail.send_email
05+
Policies

Read, write and destructive scopes per app. Approvals for risky actions. Optionally fail closed when a check can’t run.

destructive → require_approval
06+
Audit log

Every call on every plan: which agent, for which user, in which app, and which policy allowed it.

GET /v1/audit?user=u_8f2
02 · HOW IT WORKS

Connect once. Act anywhere. Stay in control.

01
Connect

Send users to Arc0 Connect, with your logo, or on your own domain on paid plans. They authorize the apps your agent needs, with only the scopes you ask for.

02
Act

Hand any agent one MCP URL for that user, or call actions from your backend over REST. Credentials never reach the model.

03
Control

Policies check every call before it reaches the app. Everything lands in the audit log, including what was blocked.

QUICKSTART.TSPREVIEW
import { Arc0 } from '@arc0/sdk'

const arc0 = new Arc0({ apiKey: process.env.ARC0_API_KEY })

// 1 · Connect: your user authorizes Gmail on your page
const { url } = await arc0.connect.createLink({
  user: 'u_8f2', customer: 'acme', app: 'gmail',
})

// 2 · Act: one MCP endpoint for any agent
const mcp = arc0.mcp.endpoint({ user: 'u_8f2' })
//   → https://mcp.arc0.ai/u/u_8f2

// …or the same connection from your backend
await arc0.actions.run('gmail.send_email', {
  user: 'u_8f2',
  input: { to: 'dana@northwind.io', subject: 'Your renewal', body },
})
// ✓ allowed · scope=write · audited▌
A⇄
Acme wants to connect to your Gmail
connect.acme.com
Read and search your emailREAD
Send email on your behalfWRITE
Delete emailNOT REQUESTED
CancelAllow
SECURED BY ACME
03 · YOUR BRAND

Your brand on the consent screen. Not ours.

Many agent platforms put their own name in front of your users at the moment of trust. Arc0 stays behind your product.

→
Your logo, colours and domain

Your logo and colours on every plan, your own domain on paid plans. No “Powered by” badge unless you want one.

→
Your own OAuth apps

On paid plans, so Google, Microsoft and Slack name you on their consent screens. Use ours while you build.

→
A connected-apps page for your users

They can see what they’ve granted and revoke it in one click.

→
Tokens you can take with you

Export them any time. Tokens issued to your own OAuth apps keep working elsewhere, so leaving never means a mass reconnect.

04 · GOVERNANCE

Governed by default. On every plan.

Your customers will ask what your agent can do in their apps, and what it did. Arc0 answers both before the question comes up.

→Read, write and destructive scopes per app
→Human approval for the actions you choose
→Optionally fail closed when a check can’t run
→Audit log on every plan, including free
POLICY · CUSTOMER acme · AGENT support-bot✓ ALLOW◐ APPROVAL✕ DENY
APPREADWRITEDESTRUCTIVE
GmailAllowAllowDeny
SlackAllowAllowDeny
SalesforceAllowApprovalApproval
GitHubAllowAllowDeny
StripeAllowDenyDeny
AUDIT LOG · 1 ENTRYBLOCKED
{
  "time": "2026-09-25T09:41:03.388Z",
  "agent": "support-bot", "user": "u_8f2", "customer": "acme",
  "action": "salesforce.delete_record", "scope": "destructive",
  "decision": "blocked", "reason": "requires approval",
  "approval": { "requested_from": "ops@acme.com", "status": "pending" }
}
05 · PRICING

Priced per connected user. Not per tool call.

ONE TASK: “REPLY TO THE CUSTOMER ABOUT THEIR RENEWAL”7 TOOL CALLS · 1 CONNECTED USER
search
read
read
read
draft
send
log
→
1 active user this month

Per-call pricing charges you seven times here, including for the retry. Arc0 charges for the user your agent works for, however many calls the task takes.

01
Unlimited calls

Within fair use. Agents retry, loop and fan out. You shouldn’t pay for every step.

02
Failed calls are free

If the app errors or a policy blocks the call, it doesn’t count.

03
Build for free

Development mode doesn’t count toward your bill, and Build is free for your first 100 active users.

04
No enterprise tax

The audit log and token export are on every plan, including free. Your own domain and OAuth apps come with paid plans.

06 · WHY ARC0

Built to be trusted with other people’s keys.

Name on your users’ consent screen
✓ARC0 Your logo on every plan; your domain and OAuth apps on paid plans
TYPICAL Often the platform’s, unless you pay extra
Your users’ tokens
✓ARC0 Exportable any time; with your OAuth apps they keep working
TYPICAL Often not exportable, so leaving means every user reconnects
Audit log
✓ARC0 Every plan, including free
TYPICAL Often an enterprise add-on
What you pay for
✓ARC0 Active connected users; calls unlimited within fair use
TYPICAL Tool calls, sometimes failed ones too
Your backend, without an agent
✓ARC0 The same connection over REST
TYPICAL A separate product and contract
Request and response payloads
✓ARC0 Not stored by default
TYPICAL Often retained by default
Who owns the company
✓ARC0 Independent. We do one thing
TYPICAL Increasingly, a larger suite
07 · APPS

The apps agents need most, done properly.

We’d rather ship the apps your agent actually uses, tested against the live API, than a catalog count. Anything else plugs in through the vendor’s official MCP server, behind Arc0’s auth, policies and audit log. See every app and its actions →

GmailEmail
SlackChat
SalesforceCRM
GitHubCode
LinearIssues
NotionDocs
Google DriveFiles
Google CalendarCalendar
OutlookEmail
Microsoft TeamsChat
Jira & ConfluenceIssues
AsanaProjects
StripePayments
FigmaDesign
+Official MCP serversBEHIND ARC0 AUTH + POLICY
?Need another app?TELL US →
08 · FAQ

Questions, answered.

Why not just build OAuth myself?

You can, for one app. Then come token refresh, per-user storage, scopes, revocation, a connect UI, verification with each provider and an audit log — for every app, forever. Arc0 is that work, done once.

Does it work with Claude, ChatGPT and Cursor?

Yes. Arc0 MCP is a standard remote MCP endpoint, so any client that supports remote MCP servers can use it. Your own agent can use the same endpoint or the SDK.

Can my backend use the connections without an agent?

Yes. The same connection is available over REST and through an authenticated proxy, so product features and agents share one connection and one bill.

Whose name do my users see when they connect?

Yours. Arc0 Connect shows your logo and colours on every plan and runs on your own domain on paid plans. With your own OAuth apps, the provider’s consent screen names you too.

Can I take my users’ tokens with me?

Yes. Tokens are exportable at any time. Tokens issued to your own OAuth apps keep working after export, so moving off Arc0 doesn’t mean asking every user to reconnect.

How is Arc0 priced?

Per active connected user per month, with calls unlimited within fair use. Failed calls and development mode are free, and audit logs are on every plan.

Do you store the data my agents read?

Arc0 stores credentials, encrypted per tenant. Request and response payloads aren’t stored by default; you can turn on short retention for debugging.

I’m on another platform today. Can I switch?

Yes. Tell us where your connections live. If they were made with your own OAuth apps and your current platform lets you export tokens, they can move without your users reconnecting.

Early access

Plug your agent in.

Early access is open for teams shipping agents that act in their users' apps. An engineer sets up your connect flow, OAuth apps and first policies with you.

MCP + REST · White-label connect · Audit log on every plan