MCP server
A remote MCP server. Add it to any MCP client with one URL and sign in with your browser: no key to paste.
mcp config (sign in with the browser)
{
"mcpServers": {
"xinf": { "url": "https://www.zinf.ai/mcp/account" }
}
}- Transport: Streamable HTTP. Each call is independent (no session).
- Sign in:
/mcp/accountanswers an unauthenticated connection with 401, so your client opens the browser. You sign in, pick a daily spending cap and click Allow; the client gets its own token. Calls use your balance, buyback token and Reward Status. - Open endpoint:
/mcpworks without a credential for the catalog tools, and the media tools can be paid per call with x402. Only the account tools (chat, balance, usage) answer 401 there. - API key:
Authorization: Bearer <key>works on both endpoints, as before.
or with an API key
{
"mcpServers": {
"xinf": {
"url": "https://www.zinf.ai/mcp",
"headers": { "Authorization": "Bearer xk_live_..." }
}
}
}Sign in (OAuth)
We implement the MCP authorization spec: OAuth 2.1 with PKCE, protected resource metadata at /.well-known/oauth-protected-resource/mcp/account, server metadata at /.well-known/oauth-authorization-server, dynamic client registration and Client ID Metadata Documents. Access tokens last an hour and refresh by themselves; refresh tokens rotate on every use.
- Consent: "Allow <app> to use your Xava Inference account", with what it can do (run models; see balance and usage) and a daily spending cap (default $5 a day, UTC). A request that would pass the cap is refused with
402 spending_cap_reachedbefore anything runs. - Connected apps: every signed-in app is listed in your dashboard under API keys, with today's spend. Change its cap or revoke it there; revoking stops it at once.
- Device login, for clients without MCP sign-in:
POST /oauth/devicegives a code you confirm at /login/device; the plugin'sxinf-loginscript does it for you and saves a connection key to~/.xinf/credentials(mode 600) without printing it.
| client | after adding the URL |
|---|---|
| Claude Code | The command ends by opening your browser: sign in, pick a daily cap, Allow. Done. If Claude Code ever says the server needs authentication: /mcp, pick plugin:xinf:xinf, Authenticate. |
| Claude Desktop | Click Connect: sign in in the browser, pick a daily cap, Allow. Team and Enterprise plans: an owner adds it under Organization settings > Connectors. |
| Codex | The command ends by opening your browser: sign in, pick a daily cap, Allow. Done. To sign in again later: codex mcp login xinf. |
| Cursor | With the Cursor CLI installed, the command ends by opening your browser: sign in, pick a daily cap, Allow. Only the app: Settings > MCP, click "Needs login" next to xinf, then Allow. Later: cursor-agent mcp login xinf. |
| Gemini CLI | Gemini asks "Authentication required for MCP Server: xinf ... Do you want to continue?": press Enter, sign in in the browser, pick a daily cap, Allow. Later: /mcp auth xinf. |
| OpenCode | The command ends by opening your browser (opencode mcp auth xinf): sign in, pick a daily cap, Allow. |
| Kimi | Choose "Trust and install", run /new, then /mcp-config login plugin-xinf:xinf: sign in in the browser, pick a daily cap, Allow. Kimi Code must be signed in (its model runs the login). |
| Pi | The command ends by opening your browser (pi "/mcp-auth xinf"): sign in, pick a daily cap, Allow. Later, inside Pi: /mcp-auth xinf. |
| Cline | In the MCP Servers panel, xinf shows Authenticate: click it, sign in in the browser, Allow (VS Code asks once to open the link back). |
| Windsurf | Refresh the MCP servers in Cascade and sign in to xinf when it asks (browser, daily cap, Allow). If Windsurf offers no sign-in, use the device login and the key config below. |
device login (any client)
curl -fsSLo xinf-login.mjs https://raw.githubusercontent.com/xavadao/xinf-plugin/main/bin/xinf-login.mjs node xinf-login.mjs export XINF_API_KEY="$(sed -n 's/^XINF_API_KEY=//p' ~/.xinf/credentials)"
Tools
| tool | account | what it does |
|---|---|---|
list_models | no | search the catalog by type, provider or name, with the list price per unit |
get_model_pricing | no | list price and Elite price for one model |
chat | yes | one chat completion on any text model (prompt or messages) |
generate_image | yes or x402 | images from a prompt; returns file URLs |
generate_video | yes or x402 | video from a prompt, by duration and resolution |
generate_audio | yes or x402 | speech from text, or music and sound from a prompt |
get_balance | yes | your available and held credit |
get_usage_summary | yes | spend, requests and buybacks over the last N days, per model |
For agents that read docs: /llms.txt (an index), /llms-full.txt (everything, with the model list) and /openapi.json (the API).