OAuth, without API keys.
Updated September 19, 2026
DialMCP uses OAuth 2.1 for the remote MCP connection. Your client starts the sign-in flow in a browser, so there is no API key to create, paste, rotate, or accidentally expose in a prompt. The URL you add is documented on the hosted MCP server endpoint page. ChatGPT's click-by-click is the ChatGPT MCP connector recipe.
First connection
- Add
https://mcp.dialmcp.com/mcpto a remote-MCP-capable client. - When the client opens the browser, sign in and verify a US or Canadian mobile number with the SMS code.
- Approve the connection and return to your client.
Your caller ID
The number you verify becomes the caller ID presented on calls you authorize. DialMCP does not spoof a number or hide behind a random caller ID. Recipients can call you back directly.
Remote connection versus stdio bridge
OAuth is used for the hosted remote endpoint. The stdio bridge exists for clients that only support local MCP servers; it launches locally and handles the same browser-based authorization flow for the hosted service. The how to build an MCP server guide shows how the browser-based flow works for any remote server. If you are containerizing your own Streamable HTTP server, put OAuth in front of the published URL; the Docker notes are on deploy an MCP server with Docker.
What OAuth does not change
Authentication does not bypass the service's safety controls. Calls remain subject to disclosure, destination-local calling hours, concurrency and frequency limits, blocked number ranges, objective screening, and permanent opt-outs. See Safety for details.
https://mcp.dialmcp.com/mcp. Same URL as the hosted MCP endpoint, the connector README, client setup examples, and MCP server configuration examples.Once connected, learn the tool lifecycle and the JSON-RPC commands the client sends, or return to the docs home.