Real OAuth, not pasted keys
OAuth 2.1 with PKCE, token introspection, and resource-scoped tokens. Your users approve access on a consent screen that carries your name — no API keys pasted into chat windows.
Hosted MCP for SaaS products
Cordboard gives your SaaS a hosted MCP endpoint — real OAuth 2.1, per-user metering, and an audit trail for every call. Bring an OpenAPI spec, or let the onboarding agent map your API without one. Live in about ten minutes.
call log
chatgpt patched to your-api
FIG. 1 — OPERATING PROCEDURE
No SDK to integrate, no OAuth server to write, nothing new to deploy on your side.
01
Paste an OpenAPI spec if you have one. No spec? Point the onboarding agent at your codebase — it reads your API and writes the tool map for you to check over.
02
Choose which endpoints agents may call. Sane defaults out of the box; write operations are opt-in, not assumed.
03
Your endpoint goes live at your-api.oncordboard.com/mcp. Claude, ChatGPT, and Cursor connect through OAuth — no API keys to paste.
The hard parts
OAuth 2.1, per-user credentials, metering, an audit trail — the parts that make an MCP server production-grade are exactly the parts the protocol doesn’t ship. Cordboard builds them in, so you don’t spend a quarter on auth instead of your product.
OAuth 2.1 with PKCE, token introspection, and resource-scoped tokens. Your users approve access on a consent screen that carries your name — no API keys pasted into chat windows.
Tool calls metered per user and logged per tenant from the first call. Plan-aware limits wired to your billing come next.
OpenAPI spec optional. The onboarding agent maps your endpoints, you approve them, and it makes the first tool call for you.
FIG. 2 — SPECIFICATIONS
| Ref | Provision |
|---|---|
| OAUTH 2.1 | Authorization code + PKCE for every end user of every tenant. |
| RFC 7662 | Token introspection — tokens are checked, not trusted. |
| RFC 9728 | Protected resource metadata, so clients discover auth correctly. |
| RFC 8707 | Resource indicators — tokens are scoped to one server, not all. |
| MCP | Streamable HTTP transport, pinned spec revision, migrations documented. |
Pricing
The enterprise MCP platforms charge compliance-budget prices. Cordboard starts free and stays under thirty dollars.
Hobby
$0 / month
Pro
$29 / month
Early-access members lock this pricing for twelve months.
Questions
The Model Context Protocol — the open standard AI tools like Claude, ChatGPT, and Cursor use to call other software. An MCP server is what makes your product callable: it lists your tools, and agents call them on your users’ behalf. Cordboard hosts that server for you.
No. A spec is the fastest path if you have one — paste it and pick your tools. If you don’t, the onboarding agent maps your API for you. If your product has no API at all yet, that’s a case we’re actively designing for — join the waitlist and tell us about it.
You can — the SDK gives you tool discovery in an afternoon. Production is the rest: an OAuth 2.1 server with PKCE and token introspection, per-user credential isolation, rate limits, metering, and an audit trail. That’s the part Cordboard does, and it’s the part that doesn’t differentiate your product.
The Hobby plan is free — one server with 1,000 tool calls a month. The Pro plan — multiple servers, 100,000 tool calls a month, usage metering, and a custom domain for your endpoint (coming soon) — is $29 a month. Early-access members lock this pricing for twelve months.
We’re admitting the first hundred in order of signup. Join the waitlist and you’ll hear from us the moment your slot is ready — we email about early access and nothing else.
Get a line
We’re patching in early customers soon. Join and you’ll hear the moment your board is ready.
We’ll only email you about Cordboard early access — never anything else, never shared. Reply to any email from us to be removed and deleted. Privacy policy.