One-Token Launcher
A single launcher that Claude boots once and lazily unlocks roughly 1,900 tools across every server your token is entitled to.
Explore One-Token LauncherStop wiring OAuth tokens and API keys into every MCP server you build. Connect your accounts once, mint a single scoped token, and reach roughly 1,900 tools across 30+ services — while MCP Factory holds the credentials and hands each server a fresh, short-lived, revocable access token at runtime.
Features
The launcher, the vault, and the access controls that make handing out a single token safe.
A single launcher that Claude boots once and lazily unlocks roughly 1,900 tools across every server your token is entitled to.
Explore One-Token LauncherOne encrypted store for every OAuth refresh token, API key, and service credential your MCP servers need.
Explore Credential VaultEntitle each token to the exact servers and tools it should reach. Different users and agents see different tool sets from the same launcher.
Explore Scoped Access TokensFresh access tokens on every request. Rotation handled — including the providers that rotate refresh tokens too.
Explore Auto OAuth RefreshDisable, rotate, or revoke a token in one place and every server drops it within about 30 seconds — no redeploy, no stale access.
Explore Instant RevocationIssue revocable mcp_xxx tokens per user. Hashed at rest, scoped to one identity, killed with one click.
Explore Per-User API Keys~1,900
Tools behind one token
30+
Integrated services
~30s
To propagate a revocation
0
Long-lived creds on a server
Pricing
Free forever if you self-host. Pro and Team plans for hosted convenience.
Self-host on your own infrastructure
Hosted MCP Factory for individuals and small teams
For teams running MCP at scale
Common Questions
Get quick answers to the questions we hear most often.
MCP Factory is a credential vault for MCP (Model Context Protocol) servers. It holds OAuth refresh tokens and API keys in one place, and hands a fresh access token to any MCP server at runtime — scoped to the right user.
Probably not. The factory pays off when you have two or more MCP servers sharing any OAuth integration, or when you use providers (Microsoft Graph, GoHighLevel) that rotate refresh tokens on every use. For a single MCP server with one user and a non-rotating provider, hand-rolled OAuth is fine.
Out of the box: Google (Ads, Search Console, Gmail, Calendar, Drive, Sheets, Docs), Microsoft Graph (OneNote, Outlook, Teams, OneDrive), GoHighLevel (agency + per-location), WordPress, and static-API-key integrations like Cloudflare, KIE.ai, Stripe, Telnyx, Anthropic, and OpenAI. Custom integrations are a config entry away.
Yes. MCP Factory is open source and ships as a Docker container (~30MB). One env var to boot — an encryption key. Run it behind any reverse proxy (Caddy, Nginx, Cloudflare Tunnel). The Free plan is “self-host whatever you want, forever”.
Free if you self-host (open source, MIT-ish). The hosted version starts at $29/mo (Pro: up to 5 users, all integrations, audit log, email support). Team is $99/mo for unlimited users with SSO and role-based access. Annual billing saves ~17%.
Start your free trial today. No credit card required.