Propolis
How it works

One grant in the hive. One token for the agent.

OAuth was designed for people clicking "Allow" in a browser. Coding agents can't do that, so most people paste long-lived secrets into config files and hope. Propolis sits in between: it does the browser part once, keeps the grant, and lets the agent borrow it one call at a time.

The three steps

  1. 1
    Connect a service

    From your dashboard, pick Google, Slack, Notion, Figma, Sentry, Atlassian, BrowserStack or Claude and approve it in your browser like any other app. Propolis receives the refresh token and stores it encrypted against your account. You can label the connection ("work Gmail", "client Slack") and connect the same service more than once.

  2. 2
    Mint a Propolis token

    Create an API token and choose which connectors it may use. Paste it into your agent's MCP configuration as a bearer header. That token is the only secret the agent ever holds, and you can delete it in one click without touching the upstream grant.

  3. 3
    Let the agent call tools

    When the agent calls a tool, Propolis checks the token, checks the connector belongs to you, checks the tool is switched on, renews the upstream credential if it is about to expire, and forwards the call. Then it writes one line to your access log describing exactly what happened.

What happens on every single call

This is the part worth reading twice. Each request from an agent goes through the same gate, in this order, and the log records where it stopped.

Check If it fails, the log says
Is the Propolis token valid?

The request is rejected with 401. Nothing is logged because no connector was identified.

Does the connector belong to the token's owner?
Blocked · ownership

The token belongs to a different account than the connector. Propolis refused the call and nothing was forwarded.

Is the token scoped to this connector?
Blocked · token scope

The API token the agent used is not scoped to this connector. Nothing was forwarded.

Is this tool switched on for the connector?
Blocked · tool off

You switched this tool off for the connector, so Propolis refused the call before it left the broker.

Is there a usable credential (renewed if needed)?
Failed · no credential

Propolis could not find a usable credential for this connector — it may need to be reconnected.

Did the service accept the call?
Failed · upstream

The call was forwarded, but the service answered with an error. Your credential was used; the result did not succeed.

All good
Delivered

Propolis attached your credential and forwarded this call to the service. The agent never saw the token.

Wiring it into Claude Code

Each connector page shows a ready-to-paste snippet. It looks like this — the only secret in it is your Propolis token.

{
  "mcpServers": {
    "google-workspace-via-propolis": {
      "url": "https://propolis.enge.io/api/proxies/google-mcp/<connector-id>",
      "headers": {
        "Authorization": "Bearer <your Propolis token>"
      }
    }
  }
}

Claude Code, Cursor, and anything else that speaks MCP over HTTP works the same way.

Questions people ask

Does the agent ever see my Google / Slack / Notion token?
No. The upstream access token is attached inside Propolis at the moment the call is forwarded. The agent only ever holds its Propolis token.
What if I revoke the grant upstream?
The next renewal fails, the connector is marked "needs reconnect" on your dashboard, and every call is logged as failed with no credential until you reconnect. Nothing is silently retried with stale secrets.
Can I limit what an agent can do?
Yes, twice over. Scope each token to specific connectors, and switch individual tools off per connector. Blocked calls show up in the log so you can see the agent tried.
How much of the call is logged?
Tool name, the arguments the agent sent (trimmed at 4 KB), which token, the outcome, and the HTTP status the service replied with. Responses are not stored.

Ready to give it a try?