CostMCP splits roles across hosts: authorization server at https://api.costmcp.com, MCP resource at https://mcp.costmcp.com.

Flow

Token prefixes

PrefixMeaning
cmcp_client_Client ID
cmcp_secret_Client secret (confidential)
cmcp_at_Access token (1h)
cmcp_rt_Refresh token (30d)

Scopes

log_usage add_expenses read_summaries estimate_costs

Protected resource

https://mcp.costmcp.com (Legacy: https://api.costmcp.com/api/mcp still works.) Manage connections from the dashboard (Connect) or Connections API.