# Connect an AI Assistant

Set up Fours MCP Server in your preferred AI assistant or code editor.

---

This guide walks you through connecting the Fours MCP Server to your preferred AI assistant or code editor. Setup takes under a minute — you just need the server URL and an [OAuth login](/mcp/setup/#sign-in-and-approve-access).

**MCP Server URL:** `https://apiv2.suger.cloud/mcp`

## Prerequisites

- A Fours account on any pricing plan
- An AI assistant or code editor that supports the Model Context Protocol (MCP)

## Claude

### Claude Desktop

1. Open **Settings** and go to **Customize** > **Connectors**
2. Click **Add custom connector**
3. Enter the following:
   - **Name:** Fours
   - **Remote MCP server URL:** `https://apiv2.suger.cloud/mcp`
4. Click **Add**, then complete the OAuth login when prompted

> Custom connectors are available on every plan (Free is limited to one connector).

### Claude Desktop (config file)

If you'd rather configure the server through a local config file:

1. Open Claude Desktop settings > **Developer** > **Edit Config**
2. Add the following to `claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "suger": {
 "url": "https://apiv2.suger.cloud/mcp"
    }
  }
}
```

3. Restart Claude Desktop

### Claude Code

```bash
claude mcp add --transport http suger https://apiv2.suger.cloud/mcp
```

Then run `/mcp` within a Claude Code session to complete authentication.

## Cursor

Open Cursor Settings > **MCP** > **Add new MCP server**, then enter:

- **Name:** Fours
- **Type:** HTTP
- **URL:** `https://apiv2.suger.cloud/mcp`

Alternatively, add this to `.cursor/mcp.json`:

```json
{
  "mcpServers": {
    "suger": {
 "url": "https://apiv2.suger.cloud/mcp"
    }
  }
}
```

## VS Code (GitHub Copilot)

Run in your terminal:

```bash
code --add-mcp '{"type":"http","name":"suger","url":"https://apiv2.suger.cloud/mcp"}'
```

Then open the MCP panel in VS Code and start the Fours server.

## Windsurf

Open Settings (`Ctrl+,` / `Cmd+,`) > **MCP Servers**, then add:

```json
{
  "mcpServers": {
    "suger": {
 "serverUrl": "https://apiv2.suger.cloud/mcp"
    }
  }
}
```

## ChatGPT

1. Go to **Settings** > **Apps**
2. Search for **Fours** — until the directory entry is renamed it may still be listed as **Suger**, our former name
3. Click **Connect** and authorize access to your Fours workspace

## Other Clients

Any MCP-compatible client can connect. Use the standard configuration:

```json
{
  "mcpServers": {
    "suger": {
 "url": "https://apiv2.suger.cloud/mcp"
    }
  }
}
```

If your client doesn't support remote MCP servers natively, use `mcp-remote` as a bridge:

```bash
npx -y mcp-remote https://apiv2.suger.cloud/mcp
```

## Sign in and approve access

The first time a client connects, it opens Fours in your browser. You sign in, choose what the
assistant can reach, and the browser hands you back to the client. The steps are the same for every
client above.

```d2
direction: right

client: "Your AI client" {
  shape: rectangle
}

signin: "Fours console sign-in page\nLog In · SSO to your organization\n(skipped if already signed in)" {
  shape: rectangle
}

login: "Fours login form\nEmail and password · Google · Microsoft" {
  shape: rectangle
}

idp: "Your identity provider\n(for example Okta)" {
  shape: rectangle
}

approve: "Authorize Application\nAuthorizing as · organizations" {
  shape: rectangle
}

client -> signin: "1. opens your browser"
signin -> login: "Log In" { style.stroke-dash: 4 }
signin -> idp: "SSO to <organization>" { style.stroke-dash: 4 }
login -> approve: "2. signed in"
idp -> approve: "2. signed in"
signin -> approve: "already signed in" { style.stroke-dash: 4 }
approve -> client: "3. Allow" { style.stroke-dash: 4 }
approve -> signin: "Use another account" { style.stroke-dash: 4 }
```

1. **Sign in.** Your client opens the **Fours console sign-in page** at `console.suger.io/login`.
   How you continue depends on how your organization signs in:

   | You are... | What to do |
   |------------|------------|
   | Already signed in to the Fours console in this browser | Nothing. The page shows *Redirecting...* and moves straight to step 2 |
   | Not using single sign-on | Click **Log In** to open the **Fours login form**, then sign in with email and password, Google or Microsoft |
   | Using single sign-on (SSO) | Click the **SSO to** button that carries your organization's name. You sign in at your company's identity provider, such as Okta. If the button isn't there, see below |

   The **SSO to** button only appears for an organization you have already signed in to with SSO in
   this browser. Until then, the page shows only **Log In**:

   ![The Fours console sign-in page with only the Log In button](images/sign-in-log-in.png)

   After you have signed in to the Fours console with SSO once in this browser, the page shows an
   **SSO to** button for each of those organizations:

   ![The Fours console sign-in page with a Log In button and an SSO to Fours button](images/sign-in-sso-to-org.png)

   If your organization's button isn't listed, sign in to the Fours console with SSO first (see
   [Okta SSO](/integrations/okta-sso/)), then connect the client again.

   **Log In** opens the Fours login form, where you can enter an email and password or choose
   **Continue with Google** or **Continue with Microsoft**:

   ![The Fours login form with email and password fields and the Continue with Google and Continue with Microsoft buttons](images/sign-in-universal-login.png)

   **SSO to** skips the Fours login form and sends you straight to your company's identity provider:

   ![An Okta sign-in page opened by Fours, titled Connecting to Fours](images/sign-in-okta.png)

   :::note
   **Requiring SSO for everyone in your organization.** By default, the Fours login form stays
   available next to SSO, so a user can still sign in with a password, Google or Microsoft. If you
   want every sign-in for your organization to go through your identity provider, contact
   [Fours support](mailto:support@suger.io). Fours turns this on for you; it can't be changed from
   the console. Once it is on, the other sign-in methods stop working for your organization's
   users, and choosing **Continue with Google** (the button highlighted above) takes them to your
   identity provider instead of signing them in with Google.
   :::

2. **Check the account.** The **Authorize Application** screen names the client asking for access
   and shows the account you're signed in as, under **Authorizing as**. If that's the wrong
   account, see [Use another account](/mcp/setup/#use-another-account).

3. **Choose access for each organization.** Every organization you belong to is listed, each with
   three choices:

   | Choice | What the assistant can do in that organization |
   |--------|------------------------------------------------|
   | **All** | Whatever your role allows, checked on every request — if your role changes, so does the assistant's access |
   | **Custom** | Only the permissions you select, and never more than your role allows. Up to three organizations can use Custom |
   | **Off** | Nothing — the assistant can't reach that organization |

4. **Click Allow.** Your browser returns to the client, which is now connected. **Deny** cancels
   the connection.

### Use another account

**Use another account** on the **Authorize Application** screen signs this browser out of Fours —
including the Fours console — and shows the Fours console sign-in page, so you can sign in as someone else. You
then come back to **Authorize Application** as that account.

:::note
It signs you out of Fours only, not out of your company's identity provider. If you sign in with
SSO and need to switch to a different person at the same company, sign out of your identity
provider first.
:::

## Verify Your Connection

After setup, try a few prompts to confirm everything is working:

```
"List my marketplace offers"
"Show recent entitlements"
"How many active buyers do I have?"
```

If the connection is successful, your assistant will prompt you to authenticate (first time only), then return live data from your Fours workspace.

## Troubleshooting

**Authentication fails**
- Ensure your Fours account has the required permissions for the operations you're attempting
- Confirm your MCP client supports OAuth 2.1 with PKCE
- Try disconnecting and reconnecting the integration

**Signed in as the wrong account**
- On the **Authorize Application** screen, click **Use another account** and sign in again — see [Use another account](/mcp/setup/#use-another-account)

**Your organization uses single sign-on**
- On the Fours console sign-in page, choose the **SSO to** button for your organization
- If it isn't listed, sign in to the Fours console with SSO in the same browser, then reconnect the client
- If you are sent to the Fours login form instead of your identity provider and your account has no password, go back to the Fours console sign-in page and use **SSO to** instead
- To make SSO mandatory for your whole organization, contact [Fours support](mailto:support@suger.io)

**An error mentions `organization` or `invalid_signature`**
- `parameter organization is not allowed for this client` can appear if an earlier **SSO to** attempt left a different organization selected in this browser. On the Fours console sign-in page, click **Log In** again; if it persists, clear this browser's site data for `console.suger.io` and reconnect
- `invalid_signature` means the sign-in link was changed or has expired. Close the tab and start the connection again from your client

**Tools not appearing**
- Double-check the server URL is exactly `https://apiv2.suger.cloud/mcp`
- Restart your MCP client after any configuration change
- Verify network connectivity to `apiv2.suger.cloud`

**Rate limit errors**
- Tool calls are not rate limited per request; a rate limit error while connecting comes from the sign-in (OAuth) endpoints, which limit attempts per minute. Wait a minute, then reconnect
- A tool that creates resources can reach one of your organization's [service quotas](/settings/quota/) — request an increase there
- Contact Fours support if the errors persist
