Which path is yours?
Personal AI agent (Grok Bot, Meta Muse, OpenClaw, Instinct, Poke, or similar) asked to integrate with Bland? Go straight to Personal AI Agents. The rest of this page is for developers and coding agents.
I'm building voice agents from a coding agent
Claude Code, Claude Desktop, Cursor, or Codex: install the Bland plugin. It bundles this server with skills,
/bland:* commands, and Norm. Other clients, or the server alone, are on the MCP clients page.I want my personal AI agent to have a phone
Setup guides and compatibility requirements for Grok Bot, Meta Muse, OpenClaw, Instinct, and Poke. Connect through MCP or REST and get a dedicated number on the Agent Phone Plan.
How it works
- Transport: Streamable HTTP (the current MCP standard). The server is stateless, so there are no sessions to manage and any request can hit any node.
- Authentication: your Bland API key in the
Authorizationheader (Bearer org_...). The key’s organization scopes every tool: an agent connected with your key sees only your org’s calls, pathways, and agents. Get a key from the dashboard, or let an agent obtain its own through the Agent onboarding API. - Rate limits: 120 requests per minute per organization.
- Safety: every tool is annotated read-only or destructive, so well-behaved clients ask before the agent does anything with side effects (like placing a real phone call). Mutating tools additionally require an explicit confirmation argument.
Discovering the server from a 401
A request that reaches/v1/mcp without a key gets a 401 that tells your agent what to do next. Two pieces:
- A
WWW-Authenticate: Bearer realm="bland"header (RFC 6750). A credential that was refused getserror="invalid_token"on the same header. - A JSON-RPC error body whose
error.messageanderror.dataname the header to send, where a human gets a key, and any self-serve signup flows an agent can run on its own: currently headless onboarding and the device-code flow. Each is listed only while it’s enabled.
Authorization header see no change.
The server intentionally does not publish an RFC 9728 resource-metadata document or a .well-known/oauth-protected-resource pointer. MCP requires that document to name an OAuth authorization server, which an API-key server does not have, and several MCP clients start an OAuth flow the moment they find one, ahead of the header the user configured.
What your agent can do
See the full tool reference.
The server also ships MCP prompts:
build_pathway and edit_pathway appear as slash commands in clients that support them (like Claude Code) and load Bland’s pathway-authoring doctrine into the session.
One endpoint, three MCP surfaces
Bland has three MCP-related surfaces. If you’re unsure, use the first one.Security notes
- Treat your API key like a password. Use environment variables or your client’s secret storage. Never commit it to a repo.
- Tools that spend money or touch live traffic (placing calls, publishing agents) are marked destructive and confirmation-gated, but review what your agent proposes before approving.
- MCP tool results can contain untrusted content (e.g. call transcripts of real conversations). Prompt-injection-aware clients like Claude Code treat tool output as data, but keep it in mind when building your own agent loops.
Next steps
MCP clients
Connect the server directly to VS Code, Windsurf, Gemini CLI, or any client, without the plugin.
Agent Phone Plan
A dedicated number with unlimited US and Canada calling and texting, built for one agent.
Tool reference
Every tool the server exposes, grouped by what it does.
Send your first call
The 5-minute API quickstart.