Skip to main content
An app connects to Leap as you. It signs in through your browser with OAuth, so you never paste a key, and Leap gives it a token that works only for the MCP server.

Signing in

  1. The app opens Leap’s sign-in page. Sign in with Google, a passkey, or an email link or code. If you’re new to Leap, the same page creates your account. When you open the email on your phone, type its 6-digit code on the computer you started from.
  2. If you’re new, Leap sets up your first workspace before it goes on: named after you, with the welcome credit. If you haven’t accepted Leap’s terms yet, you see them first.
  3. Leap asks whether to let the app use your account, and lists what it may do. The page names the website that publishes the app’s identity, such as chatgpt.com or claude.ai. Allow only apps you trust.
  4. Select Allow, and the browser hands you back to the app.
The app’s access token lasts 15 minutes, and the app renews it on its own. Each renewal is good for 30 days, so an app you use at least once a month stays connected without asking you to sign in again.

Scopes

Leap’s consent page asks for three scopes together, and shows each one in words: Every connection needs workspace:read. An app that doesn’t ask for offline_access gets no renewals, and you sign in again every 15 minutes.

Read-only connections

A connection without media:generate can search, price and read. The tools that spend, cancel or store something refuse, with a message such as:
The consent page has no switch per scope, so a connection is read-only only when the app asks for fewer scopes. To keep an agent from spending in ChatGPT or Claude, turn off its generate and generate_batch tools in the app: in Claude, set them to Blocked under Customize, Connectors, Leap; in ChatGPT, turn them off on the plugin’s page.

Workspaces

A connection acts in any workspace you belong to, with the role you have there. Every tool that reads or spends in a workspace takes an optional workspace argument, the workspace’s slug, as in app.tryleap.ai/acme.
  • If you belong to one workspace, the agent leaves workspace out and uses it.
  • If you belong to several, the agent has to name one. Without it, the tool refuses and lists your slugs, so the agent can ask you:
list_workspaces lists them with your role in each. Tell the agent which one to use, for example “use my acme workspace for Leap”, and it passes that slug on each call. search_models and get_model read the catalog, which is the same for every workspace, so they take no workspace. If you ever have no workspace, for example after leaving your only one, tools answer You have no Leap workspace yet. with a link to app.tryleap.ai. Finish setting up there and ask the agent again. You don’t need to reconnect.

Connect with an API key

For clients that can’t sign in with OAuth, such as Cursor, and for agents that run unattended, send a workspace API key instead: in the x-api-key header, or as Authorization: Bearer leap_.... A key connection works only in the key’s own workspace. list_workspaces returns that one workspace with the role api_key, and a workspace argument naming any other workspace is refused. The key’s scopes decide what the agent can do: For example, in Claude Code and Codex, with the key in LEAP_API_KEY:
A key needs generations:read to connect at all. Keys don’t renew: one works until it expires or you revoke it. New keys have both scopes, so a key connection can spend your balance. Keep it in an environment variable, and out of config files you commit.

Disconnect

In Leap, open the Connect page. Under Connected apps, select Disconnect next to the app. Leap deletes your consent and every refresh token the app holds, so it has to sign in again; the access token it already has stops working within 15 minutes. You can also remove Leap in the app itself: Removing Leap in the app deletes the app’s copy of its tokens. To be sure an app can’t come back, disconnect it in Leap too. Signing out of other devices in Leap doesn’t disconnect apps. To cut off a key connection, revoke the key at app.tryleap.ai/go/api: its next request fails.
Last modified on October 6, 2026