# Merge Agent Handler (slim) > Merge Agent Handler is a hosted MCP server from Merge API, Inc. that gives AI agents tools across more than 190 third-party connectors, with per-user credentials, tool packs, a security gateway and logs of every call. - Full: https://www.anchorterminal.com/tools/merge-agent-handler.md (~8,000 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/merge-agent-handler.json · canonical https://www.anchorterminal.com/tools/merge-agent-handler - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 69.5/100 · rank #174 of 842 · #2 in Agent tool access · not agent-ready · confidence medium** Assessment: Agent Handler's access keys can be limited to named users, tool packs and a runtime scope, with an expiry, and an agent can create an account with one documented request. No rate limit figures are published, Pro starts at $1,000 a month with no published overage rate, and failed or blocked calls spend credits. ## Facts - Kind: MCP server · vendor: Merge API, Inc. · category: Agent tool access · legal entity: Merge API, Inc. · provenance 83/100 - Endpoint: `https://ah-api.merge.dev/mcp` (Streamable HTTP, HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Merge's Master Services Agreement. The Merge CLI package `merge-api` on PyPI is marked MIT, and the repository its PyPI page links (github.com/merge-api/merge-cli) answered 404 on 8 October 2026 - Probe metrics: not measured yet (probes haven't run) - MCP endpoints: `https://ah-api.merge.dev/api/v1/tool-packs//registered-users//mcp` with an access key, or `https://ah-api.merge.dev/mcp` with OAuth sign-in. Streamable HTTP, JSON-RPC 2.0, protocol revisions 2024-11-05 to 2025-11-25 - REST API: OpenAPI 3.1 file with 69 operations on 42 paths under `/api/v1/` for connectors, tool packs, registered users, access keys, security rules, usage, files, logs and the audit log - Connectors: 190+ as of September 2026 per the docs. Merge-built connectors plus generic connectors run by outside vendors, and any remote MCP server can be registered as a custom connector - Tool naming: `__` with two underscores, such as `slack__post_message`. Meta-tools include `search_tools` and `request_tool_access`, and `authenticate_` appears while a connector has no credential - Credentials: Organisation-wide production keys, a master key that can be regenerated but not revoked, test keys for a sandbox, and API-minted keys limited by Tool Pack, Registered User, scope and expiry - End-user authorisation: Merge Link (embedded or hosted) or a magic link per Registered User and connector. OAuth, API keys and custom auth, with Merge's OAuth apps by default or the customer's own - Free plan: 2,000 credits a month, unlimited registered users and tool packs, no card. Tool calls answer 402 at the limit - Rate limits: Per Registered User and per organisation, by the minute. No figures published. Third-party limits come back as `rate_limit_exceeded` - Security Gateway: Entity rules (identity, government and financial IDs, payment, health, network), custom regex, and AI Guardrails that block or log. Guardrails let calls through if evaluation fails - Logs: Tool Call Logs and an Audit Trail kept 90 days by default, CSV export, `GET /api/v1/audit-log/`. The log endpoints for a SIEM are Enterprise only and reach back 30 days - Hosting: AWS US-East on standard plans. Enterprise contracts can add single-tenant instances, EU or APAC residency and VPC peering, per the FAQ - Certifications: SOC 2 Type II, ISO 27001, HIPAA, GDPR and CCPA per merge.dev/security, with yearly penetration tests. Reports under NDA - CLI: `merge-api` 0.5.0 on PyPI (5 October 2026), Python 3.10 or later, classified Beta. Commands include `merge search-tools`, `merge execute-tool` and `merge agent signup` - Prices: Pro plan, 25,000 credits $1000 per month (plan); Pro plan, 100,000 credits $3200 per month (plan) - Scores: Reliability 59, Performance pending, Schema & documentation 80, Agent ergonomics 68, Security & auth 83, Payments & pricing 55, Task success pending, Maintenance & community 69, Transparency & trust 71 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines. · Schema & documentation, OpenAPI 3.1 file with 69 operations, and connector tools carry `input_schema` and, where it resolves, `output_schema` (25). · Agent ergonomics, The catalogue is large (Slack alone lists 50 tools), which scores 5, plus 10 for Tool Packs with per-tool selection, the `connectors` URL sc… · Security & auth, Access keys can be limited to named Registered Users and Tool Packs and to the `runtime:all` scope, with expiry, rotation and revocation, an… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Changelog entry for Agent Handler on 2 October 2026 and Merge CLI 0.5.0 on PyPI on 5 October (30). · Transparency & trust, The editorial half. - Sources: 26, open questions: 8, both in the full twin - Capabilities: automation.apps, automation.auth, automation.actions, agent.tools, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/merge-agent-handler.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/merge-agent-handler.svg` or a link to https://www.anchorterminal.com/tools/merge-agent-handler from a page on merge.dev or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `search_tools` with a plain-language intent before `tools/list`. A Tool Pack can hold hundreds of tools and Slack alone lists 50 2. Add `?connectors=slack` to the MCP URL to limit a connection to named connectors, and `?paginated=true` only if the client follows `nextCursor` 3. Carry a user-scoped key with `runtime:all` only. The production key reaches every Registered User and the management endpoints 4. On `reauth_required` read `data.reauth_reason`, then call `authenticate_` by name. Intent search doesn't return the authenticate tools 5. Pin `MCP-Protocol-Version` to `2025-03-26` when context is tight. Later revisions repeat object results in `structuredContent` ## Connect ```bash pipx install merge-api ``` ```bash curl -X POST "https://ah-api.merge.dev/api/v1/tool-packs/$TOOL_PACK_ID/registered-users/$REGISTERED_USER_ID/mcp" \ -H "Authorization: Bearer $MERGE_AGENT_HANDLER_API_KEY" -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' ``` ```bash claude mcp add --transport http agent-handler https://ah-api.merge.dev/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/merge-agent-handler ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Composio (API + MCP) | BB | 75.1 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/composio-rube.min.md | | Zapier MCP (agent actions) | C | 58.1 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/zapier-mcp.min.md | | Pipedream API + MCP | B | 65.5 | automation.apps, automation.auth, agent.tools | https://www.anchorterminal.com/tools/pipedream.min.md | | Workato API + MCP | C | 58 | automation.apps, automation.auth, agent.tools | https://www.anchorterminal.com/tools/workato.min.md | | Tray.ai API + MCP | C | 55.5 | automation.apps, automation.auth, agent.tools | https://www.anchorterminal.com/tools/tray.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)