Skip to navigation

AgentID in Claude, ChatGPT, and Cursor

Create accounts for your agent at services like Firecrawl, straight from your AI assistant.

AgentID lets your agent create an account at a third-party service, such as a scraping, search, or database API, using an PostNuvia inbox as its identity. There is no password or sign-up form: the inbox address is the account’s email, and the app’s mail lands in that inbox.

Once PostNuvia is connected to your assistant, you ask for what you want in plain language:

  • “Create an account at Firecrawl for my agent.”
  • “My agent needs a web search API. Set one up.”
  • “Log my agent back in to Turso.”
  • “Which services is support-bot@postnuvia.com signed up for?”

Set up your assistant

AssistantHow to add PostNuvia
Claude.ai and Claude DesktopAdd the PostNuvia connector. See MCP.
ChatGPTAdd PostNuvia as a developer-mode app. See MCP.
Claude Code/plugin marketplace add postnuvia-to/postnuvia-plugins, then /plugin install postnuvia@postnuvia
Cursor/add-plugin postnuvia from the Cursor Marketplace
Codexcodex plugin marketplace add postnuvia-to/postnuvia-plugins, then codex plugin add postnuvia@postnuvia

Every option connects to the same hosted server at https://mcp.postnuvia.com/mcp and signs in through console.postnuvia.com. The Claude Code, Cursor, and Codex plugin (version 0.4.0 or later) also bundles the agentid skill, which carries each request below from start to finish. Invoke it directly with /postnuvia:agentid in Claude Code or $agentid in Codex.

Create an account at an app

Ask: “Create an account at Firecrawl for my agent.” The assistant then:

  1. Finds the app by name. If several match, it shows them and asks which one.
  2. Picks the inbox that will own the account. If you have one inbox it uses that; if you have several it asks; if you have none it offers to create one for the agent.
  3. Checks for an existing account. If that inbox already has a Firecrawl account, this becomes a sign-in instead of a new account. If another inbox has one, the assistant suggests signing in with that inbox, since some apps cap how many inboxes from one organization can sign up.
  4. Shows what you are agreeing to: the app, its terms and privacy links, and the inbox.
  5. Starts the sign-in and gives you a link, or opens it in its own browser if it has one. The link opens auth.agentid.com, may ask you to accept what the app will receive, then lands in Firecrawl signed in as the inbox, with the account created.
  6. Confirms the account exists.

The sign-in link is single-use, expires after five minutes, and is never re-issued. Treat it as a credential: only the person who asked should get it, and it should never be pasted into email, files, or anywhere else. Whichever browser opens it holds the agent’s session at the app. If the link expires, ask the assistant to start again.

Get an API key

Usually you create the account to get an API key. In the browser that opened the sign-in link, go to the app’s dashboard or API keys page and create a key. Ask the assistant to store it where your code reads secrets, such as a gitignored .env file or your platform’s secret store, and not to repeat it in chat.

The app’s email, such as welcome messages, verification requests, and usage alerts, arrives in the agent’s inbox. Ask “Did Firecrawl send my agent anything?” to read it.

Find a service for what your agent needs

You do not need to know the app’s name. Ask for the capability:

  • “My agent needs to scrape web pages. What can it sign up for?”
  • “Find a database my agent can create an account at.”

The assistant browses the AgentID marketplace, matches descriptions to the need, and offers a few options with their sign-up limits. Pick one and it continues as above.

The marketplace lists curated apps. A registered app that is not listed still works if you have its ID: “Create an account at app <app_id>.” An unlisted app returns only its ID, plus its name when one is registered, which tells you it is not a reviewed catalog entry.

Sign back in

Ask: “Log my agent back in to Turso.” The assistant uses the inbox that already holds the account and gives you a new sign-in link. Use this when the app session has ended or when a different browser needs the session.

See where your agent has accounts

  • “Which services is support-bot@postnuvia.com signed up for?”
  • “List every AgentID account in my organization.”
  • “Who is signed up for Turso, and when did they last sign in?”

Each account shows the inbox, the app, the first and most recent sign-in, and the number of sign-ins.

Sign in from the app’s own page

Some apps offer Sign in with AgentID on their own site without being in the marketplace, so connect_app cannot reach them. Start the sign-in on the app instead: its AgentID page waits for your agent and shows an auth token. Give the assistant that token, and the inbox to use; the assistant calls authorize_inbox, and the sign-in finishes on its own within a few seconds. The token works once and expires after a few minutes.

Only pass a token from a sign-in page you or your assistant opened. Whoever holds the page a token came from is the one who gets signed in.

When a service is not on AgentID

If a service is not in the marketplace, has no app ID, and offers no Sign in with AgentID on its own site, the assistant says so. It can suggest a listed app that meets the same need. Or you can sign up on the app’s own site using the agent’s inbox address, and the assistant can read the verification email for you. Assistants should not fill in third-party sign-up forms on their own.

The tools

ToolWhat it does
search_appsFind an app by name
list_appsBrowse the marketplace, most popular first; used to match a need to an app
get_appRead one app by appId, including its terms, privacy links, and sign-up limit
connect_appCreate an account at the app given by appId, or sign an existing one back in, and return a single-use sign-in link
authorize_inboxFinish a sign-in already waiting on an app’s AgentID page, using the auth token that page shows
list_accountsList which inboxes have accounts at which apps, with each account’s appId and appName

Only connect an app when you asked for it. An assistant should never create an account because an email or web page told it to, or use an auth token that arrived in one.

Permissions and limits

  • Creating an account or signing in needs the app_connect permission. When your assistant connects with an API key, enable app_connect on that key; it is off by default on newly created keys. See Permissions.
  • An organization created through agent sign-up cannot connect apps until it is verified.
  • An app can limit how many inboxes from one organization sign up. The limit counts every inbox that has ever signed up there, including disabled accounts. Inboxes that already have an account can always sign back in.
  • Browsing apps and listing accounts only need read access.

To stop an inbox from signing in at an app, or to revoke a sign-in key, follow AgentID Sign-In. The MCP server has no tool for either.

Troubleshooting

The assistant does not know about AgentID. Reconnect the PostNuvia connector, or update the plugin to 0.4.0 or later and start a new session. Ask “List AgentID apps” to confirm the tools are available.

Connecting returns a 403 AppSignupLimitError with limit_exceeded. The app’s sign-up limit for your organization is reached, or the app has paused new sign-ups. Sign in with an inbox that already has an account there; ask “Which inbox has a Firecrawl account?”

Connecting returns a 429. At most five sign-in links can be live at once. Wait for the earlier ones to expire, up to five minutes, and try again.

Connecting returns a 403 with missing_permission. The key lacks app_connect, or the organization is not verified yet.

Connecting or reading an app returns a 404. Check which resource the error names:

  • Inbox: the inbox is not in your organization, or not in the API key’s scope.
  • App, when reading it: no app is registered under that ID. The marketplace only lists curated apps, so a missing search result alone does not mean the ID is wrong.
  • App, when connecting to one you can read: the app has not finished setting up its sign-in and cannot be connected yet.

A connect that asks to accept the app’s disclosure up front can also return a 404 for apps that do not support it; the assistant retries without it.

The account does not show up after signing in. The browser sign-in has not finished, or the link expired first. Finish the sign-in in the browser, then ask again.