docs
docs

MCP server

A remote MCP server. Add it to any MCP client with one URL and sign in with your browser: no key to paste.

mcp config (sign in with the browser)
{
  "mcpServers": {
    "xinf": { "url": "https://zinf.ai/mcp/account" }
  }
}
  • Transport: Streamable HTTP. Each call is independent (no session).
  • Sign in: /mcp/account answers an unauthenticated connection with 401, so your client opens the browser. You sign in, pick a daily spending cap and click Allow; the client gets its own token. Calls use your balance, buyback token and Reward Status.
  • Open endpoint: /mcp works without a credential for the catalog tools, and the media tools can be paid per call with x402. Only the account tools (chat, balance, usage) answer 401 there.
  • API key: Authorization: Bearer <key> works on both endpoints, as before.
or with an API key
{
  "mcpServers": {
    "xinf": {
      "url": "https://zinf.ai/mcp",
      "headers": { "Authorization": "Bearer xk_live_..." }
    }
  }
}

Sign in (OAuth)

We implement the MCP authorization spec: OAuth 2.1 with PKCE, protected resource metadata at /.well-known/oauth-protected-resource/mcp/account, server metadata at /.well-known/oauth-authorization-server, dynamic client registration and Client ID Metadata Documents. Access tokens last an hour and refresh by themselves; refresh tokens rotate on every use.

  • Consent: "Allow <app> to use your Xava Inference account", with what it can do (run models; see balance and usage) and a daily spending cap (default $5 a day, UTC). A request that would pass the cap is refused with 402 spending_cap_reached before anything runs.
  • Connected apps: every signed-in app is listed in your dashboard under API keys, with today's spend. Change its cap or revoke it there; revoking stops it at once.
  • Device login, for clients without MCP sign-in: POST /oauth/device gives a code you confirm at /login/device; the plugin's xinf-login script does it for you and saves a connection key to ~/.xinf/credentials (mode 600) without printing it.
clientafter adding the URL
Claude CodeThe command ends by opening your browser: sign in, pick a daily cap, Allow. Done. If Claude Code ever says the server needs authentication: /mcp, pick plugin:xinf:xinf, Authenticate.
Claude DesktopClick Connect: sign in in the browser, pick a daily cap, Allow. Team and Enterprise plans: an owner adds it under Organization settings > Connectors.
CodexThe command ends by opening your browser: sign in, pick a daily cap, Allow. Done. To sign in again later: codex mcp login xinf.
CursorWith the Cursor CLI installed, the command ends by opening your browser: sign in, pick a daily cap, Allow. Only the app: Settings > MCP, click "Needs login" next to xinf, then Allow. Later: cursor-agent mcp login xinf.
Gemini CLIGemini asks "Authentication required for MCP Server: xinf ... Do you want to continue?": press Enter, sign in in the browser, pick a daily cap, Allow. Later: /mcp auth xinf.
OpenCodeThe command ends by opening your browser (opencode mcp auth xinf): sign in, pick a daily cap, Allow.
KimiChoose "Trust and install", run /new, then /mcp-config login plugin-xinf:xinf: sign in in the browser, pick a daily cap, Allow. Kimi Code must be signed in (its model runs the login).
PiThe command ends by opening your browser (pi "/mcp-auth xinf"): sign in, pick a daily cap, Allow. Later, inside Pi: /mcp-auth xinf.
ClineIn the MCP Servers panel, xinf shows Authenticate: click it, sign in in the browser, Allow (VS Code asks once to open the link back).
WindsurfRefresh the MCP servers in Cascade and sign in to xinf when it asks (browser, daily cap, Allow). If Windsurf offers no sign-in, use the device login and the key config below.
device login (any client)
curl -fsSLo xinf-login.mjs https://raw.githubusercontent.com/xavadao/xinf-plugin/main/bin/xinf-login.mjs
node xinf-login.mjs
export XINF_API_KEY="$(sed -n 's/^XINF_API_KEY=//p' ~/.xinf/credentials)"

Tools

toolaccountwhat it does
list_modelsnosearch the catalog by type, provider or name, with the list price per unit
get_model_pricingnolist price and Elite price for one model
chatyesone chat completion on any text model (prompt or messages)
generate_imageyes or x402images from a prompt; returns file URLs
generate_videoyes or x402video from a prompt, by duration and resolution
generate_audioyes or x402speech from text, or music and sound from a prompt
get_balanceyesyour available and held credit
get_usage_summaryyesspend, requests and buybacks over the last N days, per model

For agents that read docs: /llms.txt (an index), /llms-full.txt (everything, with the model list) and /openapi.json (the API).