Skip to content
Docs

Sign-in and API keys

How MCP sign-in works, when you need an API key instead, and how to create, copy and revoke keys.

Updated 1 October 2026Open in DocStoX
On this page

DocStoX's MCP server accepts two kinds of credential. Which one you use depends on your client, not on your plan: both reach the same tools and the same usage limits.

How it worksUse it for
Sign in with DocStoXYour app opens a docstox.com page and you approve the connection. Your app never sees your password.Claude, ChatGPT, Claude Code, VS Code
API keyYou create a key that starts with dox- and your app sends it as Authorization: Bearer dox-...Cursor, Windsurf, Gemini CLI, Codex, and any client without sign-in

Signing in

When a client signs in, it opens a page at docstox.com. Sign in with Google or your DocStoX email and password if you are not already signed in. DocStoX then shows what the app is asking for:

  • Look up stocks, fundamentals, screens and market data.
  • Read your DocStoX portfolio and watchlists.

It also states plainly that the app cannot trade, change your account, or see your password. Click Allow to finish, or Cancel to stop.

Each connected app shows up at /mcp/keys under Connected Apps, with when it first connected and when it was last used.

Revoking a connected app

Open /mcp/keys, find the app under Connected Apps, and select Revoke. The app stops being able to use DocStoX tools on its next call; it needs to sign in again to reconnect. This cannot be undone from the app's side.

API keys

An API key is a personal credential for clients that cannot complete a sign-in flow, such as a local CLI reading a config file.

  1. Create a key

    Open /mcp/keys and select Create Token. Give it a name you will recognise later, such as "Cursor laptop".

  2. Copy it once

    The full key is shown exactly once, in the form dox-.... Copy it now: DocStoX only ever stores a hash of it and cannot show it to you again.

  3. Add it to your client

    Paste it into your client's configuration as a Bearer token: Authorization: Bearer dox-YOUR_KEY_HERE. Setup steps for each client are in Claude Code, Cursor and other clients.

You can have up to 10 active keys at a time. Each key's row on /mcp/keys shows its prefix and last 4 characters, when it was created, and when it was last used, so you can tell your keys apart without ever seeing the full value again.

Renaming and revoking a key

Rename a key any time from its row. To revoke one, select Revoke: any client still using that key stops working immediately, and this cannot be undone. Create a new key to replace it.

Checking your usage

/mcp/keys also shows your tool calls today and over the last 30 days against your plan's limit, and a breakdown of calls by tool and by which key or connected app made them. Details: Usage and limits.

Was this page helpful?

Something wrong or missing on this page? Email [email protected]