One plug. Every app.
Any agent.
Your users connect their apps once, under your brand. Your agent, or Claude, ChatGPT and Cursor, acts through one MCP endpoint, limited to what each user approved, with every action on the record.
Everything between your agent and your users’ apps.
The flow your users authorize apps in, with your logo and colours. Your own domain and OAuth apps on paid plans.
Credentials encrypted per tenant and refreshed before they expire. OAuth, API keys and basic auth.
One endpoint per user. Point your own agent, Claude, ChatGPT or Cursor at it.
The same connection from your backend, with no agent in the loop. One connection, two callers.
Read, write and destructive scopes per app. Approvals for risky actions. Optionally fail closed when a check can’t run.
Every call on every plan: which agent, for which user, in which app, and which policy allowed it.
Connect once. Act anywhere. Stay in control.
Send users to Arc0 Connect, with your logo, or on your own domain on paid plans. They authorize the apps your agent needs, with only the scopes you ask for.
Hand any agent one MCP URL for that user, or call actions from your backend over REST. Credentials never reach the model.
Policies check every call before it reaches the app. Everything lands in the audit log, including what was blocked.
import { Arc0 } from '@arc0/sdk' const arc0 = new Arc0({ apiKey: process.env.ARC0_API_KEY }) // 1 · Connect: your user authorizes Gmail on your page const { url } = await arc0.connect.createLink({ user: 'u_8f2', customer: 'acme', app: 'gmail', }) // 2 · Act: one MCP endpoint for any agent const mcp = arc0.mcp.endpoint({ user: 'u_8f2' }) // → https://mcp.arc0.ai/u/u_8f2 // …or the same connection from your backend await arc0.actions.run('gmail.send_email', { user: 'u_8f2', input: { to: 'dana@northwind.io', subject: 'Your renewal', body }, }) // ✓ allowed · scope=write · audited▌
Your brand on the consent screen. Not ours.
Many agent platforms put their own name in front of your users at the moment of trust. Arc0 stays behind your product.
Your logo and colours on every plan, your own domain on paid plans. No “Powered by” badge unless you want one.
On paid plans, so Google, Microsoft and Slack name you on their consent screens. Use ours while you build.
They can see what they’ve granted and revoke it in one click.
Export them any time. Tokens issued to your own OAuth apps keep working elsewhere, so leaving never means a mass reconnect.
Governed by default. On every plan.
Your customers will ask what your agent can do in their apps, and what it did. Arc0 answers both before the question comes up.
| APP | READ | WRITE | DESTRUCTIVE |
|---|---|---|---|
| Allow | Allow | Deny | |
| Allow | Allow | Deny | |
| Allow | Approval | Approval | |
| Allow | Allow | Deny | |
| Allow | Deny | Deny |
{
"time": "2026-09-25T09:41:03.388Z",
"agent": "support-bot", "user": "u_8f2", "customer": "acme",
"action": "salesforce.delete_record", "scope": "destructive",
"decision": "blocked", "reason": "requires approval",
"approval": { "requested_from": "ops@acme.com", "status": "pending" }
}Priced per connected user. Not per tool call.
Per-call pricing charges you seven times here, including for the retry. Arc0 charges for the user your agent works for, however many calls the task takes.
Within fair use. Agents retry, loop and fan out. You shouldn’t pay for every step.
If the app errors or a policy blocks the call, it doesn’t count.
Development mode doesn’t count toward your bill, and Build is free for your first 100 active users.
The audit log and token export are on every plan, including free. Your own domain and OAuth apps come with paid plans.
Built to be trusted with other people’s keys.
The apps agents need most, done properly.
We’d rather ship the apps your agent actually uses, tested against the live API, than a catalog count. Anything else plugs in through the vendor’s official MCP server, behind Arc0’s auth, policies and audit log. See every app and its actions →
Questions, answered.
You can, for one app. Then come token refresh, per-user storage, scopes, revocation, a connect UI, verification with each provider and an audit log — for every app, forever. Arc0 is that work, done once.
Yes. Arc0 MCP is a standard remote MCP endpoint, so any client that supports remote MCP servers can use it. Your own agent can use the same endpoint or the SDK.
Yes. The same connection is available over REST and through an authenticated proxy, so product features and agents share one connection and one bill.
Yours. Arc0 Connect shows your logo and colours on every plan and runs on your own domain on paid plans. With your own OAuth apps, the provider’s consent screen names you too.
Yes. Tokens are exportable at any time. Tokens issued to your own OAuth apps keep working after export, so moving off Arc0 doesn’t mean asking every user to reconnect.
Per active connected user per month, with calls unlimited within fair use. Failed calls and development mode are free, and audit logs are on every plan.
Arc0 stores credentials, encrypted per tenant. Request and response payloads aren’t stored by default; you can turn on short retention for debugging.
Yes. Tell us where your connections live. If they were made with your own OAuth apps and your current platform lets you export tokens, they can move without your users reconnecting.
Plug your agent in.
Early access is open for teams shipping agents that act in their users' apps. An engineer sets up your connect flow, OAuth apps and first policies with you.
MCP + REST · White-label connect · Audit log on every plan