1. Get a verify key#
Sign up at app.delegus.ai with your work email. The sandbox is free, with no card. Copy the verify key on the "your organization is ready" screen; it starts with dk_rp_. It is shown once, and you can mint more under Keys in the console.
The verify key lets your service check agent requests. It cannot administer your organization.
2. Add it to Vercel Connect#
In your Vercel team, open Connect. Delegus has been submitted to the Connect directory; once Vercel publishes it, choose Delegus under Browse Connectors. Until then, create an API-key connector. Either way, paste your verify key and link the projects that should use it.
3. Check each agent request#
Install both SDKs:
npm install @vercel/connect @delegus/sdkFetch the key from Connect, then check the request before you act on it:
import { getToken } from '@vercel/connect';
import { Delegus } from '@delegus/sdk';
const apiKey = await getToken('<your connector uid>', { subject: { type: 'app' } });
const delegus = new Delegus({ apiKey });
const d = await delegus.verify({ grant, proof, action });
if (d.decision !== 'ALLOW') return refuse(d.reason); // keep d.receipt either wayYour connector's uid is shown on the connector in the Vercel dashboard. The Connect SDK caches the key in your function's process, so it is not fetched again on every request.
grant, proof and action come from the agent's request, exactly as in Integrate as a relying party. Proceed only on ALLOW, and keep the signed receipt with the order.
MCP servers on Vercel#
If your MCP server runs on Vercel, pass the same key to the one-line middleware in MCP servers.
Local development#
Run vercel link, then vercel env pull. That writes a short-lived Vercel token to .env.local, which the Connect SDK uses to fetch your key locally.