Connect ChatGPT or another AI assistant
Sign in, choose what the assistant can access, and manage approvals in your dashboard.
The hosted connection lets a compatible AI assistant inspect and manage your BlazingFast services. You do not need to install an SDK or create a personal API key.
Connect your account
- Open Settings → API → MCP and copy the hosted MCP endpoint.
- Add BlazingFast to your AI client. If you are creating a custom ChatGPT connection, use its MCP connection flow and paste the endpoint you copied from Settings → API.
- Select OAuth authentication and complete the BlazingFast sign-in and consent screen.
- Select the permissions you want to grant.
- Open a new conversation, select the BlazingFast app, and ask it to list your services.
Custom ChatGPT connections depend on your plan and workspace settings. OpenAI's connection instructions describe the current setup. If a client requires an OAuth client ID and secret, use the credentials registered for that client; contact support if they have not been issued. A personal API key or your account password will not work in those fields.
Choose an access policy
Open Settings → AI connections, select the connection, and use the on/off checkboxes to choose permissions.
| Policy | Viewing | Changes |
|---|---|---|
| Read only | Selected viewing permissions | Blocked |
| Write with approval | Selected viewing permissions | Wait for your dashboard approval |
| Full access | Selected viewing permissions | Execute automatically when permitted |
Full access requires acknowledgement because selected actions can spend balance, interrupt a server, reinstall it, or terminate a service. Your AI client may also ask for confirmation.
Older connections keep their previous rules until you save a new policy. In Write with approval, even starting a server, creating an order and paying an invoice require approval. Check the policy shown on your connection when an action is blocked.
Try a first request
- “Show my VPS status, installed OS and IP addresses.”
- “List unpaid invoices and my account balance.”
- “Show the DNS records for example.com.”
- “Find VPS plans available in the Netherlands with Ubuntu, and show the monthly price.”
The assistant can resolve a service from your list using its hostname or IP. If several services match, select the intended one. IP addresses, installed OS and usage may be unavailable for some services; missing values are not zero.
Approve and track a change
Under Write with approval, review the target and requested change in AI connections. Approve or reject the pending request there. The assistant should track the returned operation request rather than submitting the same action again.
Draft order creation produces an unpaid invoice, followed by a separate payment request. Atomic POST /v1/deploy/... instead authorizes payment of the full final order amount from account balance and queued provisioning in the same request. A balance payment can activate provisioning and may be partial if the available balance does not cover the outstanding amount.
Purchase discovery and execution recovery
Hosted MCP uses https://mcp.blazingfast.io/mcp and your OAuth connection policy. Local MCP uses the installed SDK/CLI 0.1.17 and your API credentials. Discover the tools actually exposed by the client; their names differ:
- Optional quote: hosted quote_product_variant; local bf_product_variant_quote.
- Execution receipt: hosted get_operation; local bf_operation_get.
- Original-key recovery: hosted recover_operation; local bf_operation_recover.
For both recovery tools, the argument is idempotency_key, even though hosted write tools use request_key. This example recovers an existing VPS reboot; substitute the exact original key and owned service UUID:
{
"idempotency_key": "ORIGINAL_KEY",
"method": "POST",
"path": "/v1/vps/SERVICE_UUID/reboot"
}Recovery is read-only and does not repeat a mutation. Supply method and path together when needed and credential_id only to select the original credential. Reads require current account access and the matching operation-read scope.
Hosted deploy_product is the preferred canonical atomic-purchase workflow. Discover purchase eligibility and configuration first; never invent product/variant IDs, OS codes, SSH-key IDs or regions. A quote is optional, and max_total is the authorized spending ceiling. Hosted writes use request_key as the server Idempotency-Key and honor Read only, Write with approval or Full access. get_operation_request tracks dashboard approval; get_operation tracks execution. Approval is not completion.
Local bf_product_variant_deploy is available only when selected mutations are enabled with BF_API_MCP_ENABLE_MUTATIONS set to 1. It executes under API-key scopes without hosted dashboard approval. Both interfaces retain separate credential controls; execution receipts never expose passwords or private keys. DNSSEC has local tools and its own state contract, with no hosted DNSSEC tool.
See purchase policies, receipt statuses and recovery limitations.
Update or disconnect
Change permissions or revoke the connection from AI connections. If the needed permission is outside the original consent, reconnect to grant it. Refresh the app's tool list after tool updates. Saved permission changes invalidate older pending requests, but cannot undo an action already dispatched.
Passwords and private keys are never returned through the hosted connection. Use your service details in the dashboard for credential access.

