What you need
- A Vercel project linked to your local directory with
vercel link - An Agent Loadout organization in which you are an owner or admin, because only they can approve a connection
- The agent your app should act as
How the connection works
- Vercel Connect reads the discovery document at
https://agent-loadout.com/.well-known/oauth-authorization-serverand registers itself as an OAuth client. Agent Loadout does not issue client secrets, so you have nothing to copy. - The first token request for a user sends that person to the Agent Loadout consent screen. They sign in, choose the organization and the agent, and tick the permissions. This creates an agent token that appears on the agent’s Tokens tab under the connector’s name.
- From then on, Vercel Connect refreshes the grant in the background. Access tokens last one hour. Refresh tokens rotate on every use and expire after 90 days without use.
https://agent-loadout.com/api/mcp and with the REST API at https://agent-loadout.com/api/v1.
Set up the connector
Call the REST API
getToken returns a current access token for one subject. Use a stable ID from your app’s own session as the subject.
app/lib/agent-loadout.ts
getToken throws UserAuthorizationRequiredError. Show a “connect your account” button in that case.
Use the MCP server with the AI SDK
connectAuthProvider asks Vercel Connect for a token before each MCP request:
app/api/chat/route.ts
Permissions
Each token carries every permission approved for that grant. Agent Loadout does not narrow a token below its grant, so if parts of your app need different permissions, create a connector for each part. When a tool or endpoint needs a permission the grant lacks, the request fails with a permission error. Approve the connection again with the extra scope.Disconnect
Revoke the token on the agent’s Tokens tab, or revoke the grant in Vercel with the dashboard, the CLI or the SDK’srevokeToken. Vercel Connect calls the Agent Loadout revocation endpoint, so the agent token stops working immediately. Deleting the connector revokes its tokens as well.
Troubleshooting
The token request fails with invalid_target
The token request fails with invalid_target
Agent Loadout issues tokens only for
https://agent-loadout.com/api/mcp and https://agent-loadout.com/api/v1. Remove any other value from the resources option.The consent screen rejects my account
The consent screen rejects my account
Only owners and admins of an organization can connect its agents. Ask an owner to approve the connection or to change your role.
getToken throws NoValidTokenError
getToken throws NoValidTokenError
The grant has been revoked, or its refresh token went unused for 90 days. Approve the connection again.