Stytch for AI agents

Stytch is an authentication and identity platform; through Arc0 an agent manages Stytch project settings, redirect URLs, SDK configuration, and email templates. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityOAuth 2.0 (MCP)MCP + RESTstytch.com
AUDIT LOG · STYTCHPOLICY: acme-support
09:41:07 · claude · u_8f2read
stytch.list_projects
Listprojects✓ allowed · 212ms
09:41:08 · claude · u_8f2read
stytch.get_b2_bsdk_config
Getb2bsdkconfig✓ allowed · 164ms
09:41:09 · claude · u_8f2write
stytch.create_secret
Createsecret✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
stytch.delete_secret
Deletesecret✕ blocked · policy: deny
EVERY STYTCH CALL, ON THE RECORD
01 · USE CASES

What agents do in Stytch.

01

List redirect URLs before editing

Pull all configured redirect URLs for a project before adding or removing one, so nothing breaks silently.

02

Draft a new email template

Draft a new email template, such as a magic-link email, for the team to review before it goes live.

03

Delete a redirect URL with approval

Remove a redirect URL only after the user confirms the old domain is fully retired.

02 · ACTIONS

21 Stytch actions, graded by risk.

Every Stytch action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

7

Look things up. Allowed by default.

  • stytch.list_projects
    Listprojects
  • stytch.get_b2_bsdk_config
    Getb2bsdkconfig
  • stytch.get_all_public_tokens
    Getallpublictokens
  • stytch.get_all_redirect_ur_ls
    Getallredirecturls
  • stytch.get_all_email_templates
    Getallemailtemplates
  • stytch.get_consumer_sdk_config
    Getconsumersdkconfig
  • stytch.get_password_strength_config
    Getpasswordstrengthconfig

write

10

Create and change things. Allow, or ask the user first.

  • stytch.create_secret
    Createsecret
  • stytch.create_project
    Createproject
  • stytch.create_public_token
    Createpublictoken
  • stytch.create_redirect_url
    Createredirecturl
  • stytch.update_redirect_url
    Updateredirecturl
  • stytch.create_email_template
    Createemailtemplate
  • stytch.update_b2_bsdk_config
    Updateb2bsdkconfig
  • stytch.update_email_template
    Updateemailtemplate
  • stytch.update_consumer_sdk_config
    Updateconsumersdkconfig
  • stytch.set_password_strength_config
    Setpasswordstrengthconfig

destructive

4

Delete, cancel or archive. Ask first, or deny outright.

  • stytch.delete_secret
    Deletesecret
  • stytch.delete_public_token
    Deletepublictoken
  • stytch.delete_redirect_url
    Deleteredirecturl
  • stytch.delete_email_template
    Deleteemailtemplate
03 · HOW IT WORKS

Stytch in three steps.

  1. 01Your users connect StytchThey sign in to Stytch on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “createsecret” can wait for the user, and “deletesecret” can be denied outright.
  3. 03Any agent can actYour agent calls Stytch through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('stytch', {
  read: 'allow',
  write: 'ask',        // create_secret
  destructive: 'deny',  // delete_secret
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Stytch connects.

Stytch runs its own MCP server behind OAuth. Arc0 registers the client, users approve access on Arc0 Connect, and your agent reaches Stytch through the same endpoint, policies and audit log as every other app.

The same Stytch connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0 (MCP)
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Stytch from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Stytch and Arc0, answered.

Q01

Can I use Stytch with Claude, ChatGPT or Cursor?

Yes. Connect Stytch to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Stytch actions you allow.

Q02

How do users connect Stytch?

Stytch runs its own MCP server behind OAuth. Arc0 registers the client, users approve access on Arc0 Connect, and your agent reaches Stytch through the same endpoint, policies and audit log as every other app.

Q03

Which Stytch actions can my agent take?

21 in total: 7 read, 10 write and 4 destructive, such as “createsecret”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Stytch?

Yes. Actions like “deletesecret” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Stytch too?

Yes. The same Stytch connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Stytch into your agent.

Your users connect Stytch once, under your brand. Your agent gets 21 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan