# How do I use a ZeroTwo Site as an MCP server?

> A published Site can serve its own MCP endpoint at /mcp behind ZeroTwo sign-in. See what it needs, how you approve a connection and what it does not do.

Source: https://help.zerotwo.ai/en/articles/20001547-how-do-i-use-a-zerotwo-site-as-an-mcp-server
Section: ZeroTwo Sites
Last updated: 2026-10-05

A published Site can also act as an MCP server: a set of tools that an AI app can call. The server lives at the `/mcp` path of the Site's address, for example `https://your-site.zerotwo.site/mcp`, and it is protected by ZeroTwo sign-in. You connect to it by adding it as an MCP server yourself.

## What the Site needs

- **An MCP endpoint in the Site.** The Sites starter has add-ons for a database, file storage and sign-in, but none for MCP. The endpoint is code in your Site that speaks the MCP protocol at `/mcp` over streamable HTTP.
- **A live published version.** ZeroTwo only treats the endpoint as ready when the Site's current live version answers an MCP initialization. A private preview deployment does not count, and an ordinary web page at `/mcp` does not count either.

To check, ask ZeroTwo in the Site's chat for the Site's MCP connection details. When the endpoint is ready, it gives you the server URL. When it is not, there are no details to give you.

## Which tools it offers

ZeroTwo does not define the tools. They are whatever your Site's own code exposes. ZeroTwo's readiness check only opens the connection: it never lists or calls your Site's tools. These are separate from the tools ZeroTwo itself uses to build, deploy and share Sites.

## Connect to the Site

1. Open **Customize** and select **Add**, or open **Settings** > **Plugins** and select **Add**. Choose **Add MCP server**.
2. Enter a name, choose **Streamable HTTP** as the type, and paste the Site's `/mcp` address as the URL.
3. Under **Authentication**, choose **OAuth 2.0**. It redirects you to the provider to authorize and works with public addresses, which a Site's address is.
4. When ZeroTwo sends you to the Site's authorization page, check the details and select **Allow connection**.

The full form is described in [Add your own MCP server and use MCP Apps in ZeroTwo](https://help.zerotwo.ai/en/articles/12584461-add-your-own-mcp-server-and-use-mcp-apps-in-zerotwo). Other AI apps can connect the same way if they support the standard MCP sign-in flow: they register themselves, use an S256 PKCE challenge, ask for the `mcp` scope and use the Site's exact `/mcp` address as the resource. Their callback address has to be HTTPS, or HTTP on a loopback address such as localhost.

## What the authorization page shows

The page is headed **Connect to your Site**. It names the app asking for access, the Site, the address it will return to, and says the app wants to use the tools and data the Site provides with your Site permissions. Choose **Allow connection** or **Deny**. Nothing is approved just because you are signed in. Anyone who has access to the Site, as owner, editor or viewer, can be asked to approve a connection.

## Access and expiry

- Even a public Site's `/mcp` endpoint needs this sign-in. An app without it is turned away.
- An approved app gets an access credential that lasts five minutes and a refresh credential that is replaced each time it is used. Each refresh credential has an absolute life of 30 days, so after that the app asks you to allow the connection again. Reusing a refresh credential that was already replaced revokes the whole grant.
- The connection follows the Site's access. If the Site's access changes or your own access ends, the app has to be authorized again.

## Related articles

Who can reach the Site, and so who can approve a connection, is decided by the Site's sharing settings. See [How do I build, publish and manage a website with ZeroTwo Sites?](https://help.zerotwo.ai/en/articles/20001339-how-do-i-build-publish-and-manage-a-website-with-zerotwo-sites) for those, and [Add, use and manage plugins in ZeroTwo](https://help.zerotwo.ai/en/articles/20001256-add-use-and-manage-plugins-in-zerotwo) for plugins.
