Hosted OAuth (recommended first)
The User Intuition MCP server is available at:Authorization: Bearer ui_sk_… header. The server validates the key and its scopes with the backend on every request, so revocation takes effect without a separate hosted MCP login. Call get_account to verify the effective workspace before running tools.
stdio clients
Claude Desktop, Cursor, Claude Code, and VS Code can launch the MCP server locally. SetUSERINTUITION_API_KEY to a key created under Settings → API Keys. New keys start with read access; choose write or paid-action permissions when creating one if the local agent needs them.
Keep API keys out of source control, screenshots, prompts, and shared configuration files. Rotate a key immediately if it is exposed.
Authorization behavior
Every backend request is scoped to the authenticated account. Resource reads, updates, and deletes also perform ownership checks. A valid OAuth session or API key can still receive403 or 404 when the requested resource is not accessible.
Platform admins with users.role = admin can call list_organizations and read public research across organizations. Pass organization_id to an MCP tool to select one for account-scoped reads or changes; it is required before changing another organization’s study or using its wallet. Organization owner/admin membership alone does not grant this access. An admin API key still needs the tool’s scopes and paid-action spend cap. See platform admin access.
read permits study and result retrieval, including search and estimates. write permits non-paid changes. Paid launch_panel requires write and panel:launch; send_participant_reward requires write and rewards:send. Paid API keys also require a positive lifetime USD cap. The amount reserved for an uncertain paid operation continues to count against that cap until reconciled. OAuth clients must request the corresponding scopes for hosted tools. These grants allow a call, but a human still approves the plan and each spend through the tool workflow.

