Skip to main content
An app or agent on Vercel usually reaches Agent Loadout with an agent token stored as an environment variable. Vercel Connect removes that secret: it keeps the OAuth grant on Vercel’s side, and your code asks for a one-hour access token whenever it needs one. Each grant is bound to one agent and to the permissions someone approved on the Agent Loadout consent screen.

What you need

  • A Vercel project linked to your local directory with vercel link
  • An Agent Loadout organization in which you are an owner or admin, because only they can approve a connection
  • The agent your app should act as

How the connection works

  1. Vercel Connect reads the discovery document at https://agent-loadout.com/.well-known/oauth-authorization-server and registers itself as an OAuth client. Agent Loadout does not issue client secrets, so you have nothing to copy.
  2. The first token request for a user sends that person to the Agent Loadout consent screen. They sign in, choose the organization and the agent, and tick the permissions. This creates an agent token that appears on the agent’s Tokens tab under the connector’s name.
  3. From then on, Vercel Connect refreshes the grant in the background. Access tokens last one hour. Refresh tokens rotate on every use and expire after 90 days without use.
The same access token works with the MCP server at https://agent-loadout.com/api/mcp and with the REST API at https://agent-loadout.com/api/v1.

Set up the connector

Call the REST API

getToken returns a current access token for one subject. Use a stable ID from your app’s own session as the subject.
app/lib/agent-loadout.ts
If that user has not approved access yet, getToken throws UserAuthorizationRequiredError. Show a “connect your account” button in that case.

Use the MCP server with the AI SDK

connectAuthProvider asks Vercel Connect for a token before each MCP request:
app/api/chat/route.ts
The Vercel guide for the AI SDK and MCP covers streaming and tool approval in full. Add tool approval for tools that send mail, spend money or run commands.

Permissions

Each token carries every permission approved for that grant. Agent Loadout does not narrow a token below its grant, so if parts of your app need different permissions, create a connector for each part. When a tool or endpoint needs a permission the grant lacks, the request fails with a permission error. Approve the connection again with the extra scope.

Disconnect

Revoke the token on the agent’s Tokens tab, or revoke the grant in Vercel with the dashboard, the CLI or the SDK’s revokeToken. Vercel Connect calls the Agent Loadout revocation endpoint, so the agent token stops working immediately. Deleting the connector revokes its tokens as well.

Troubleshooting

Agent Loadout issues tokens only for https://agent-loadout.com/api/mcp and https://agent-loadout.com/api/v1. Remove any other value from the resources option.
The grant has been revoked, or its refresh token went unused for 90 days. Approve the connection again.