Universal endpoint
https://mcp.expulse.app/mcpThe production URL stays the same for every user. OAuth resolves the person and workspace on every request.
Connect trusted AI clients to Expulse without copying a permanent API token into a settings box.
https://mcp.expulse.app/mcpThe production URL stays the same for every user. OAuth resolves the person and workspace on every request.
Expulse publishes protected-resource metadata and relies on Auth0 discovery, authorization, consent, rotation, issuer, audience, expiry, and scope validation.
expulse:readexpulse:draftexpulse:executeexpulse:enrichSubscription, billing pause, sender ownership, credits, workspace membership, and per-user idempotency are checked inside Expulse—not trusted to the AI client.
Trusted founding users connect through developer mode first. Expulse will submit a universal-URL plugin only after OAuth, disclosures, annotations, tests, and review credentials pass production validation.