1. Run init
.env.local as VENDO_API_KEY and vendo_make runs on it. Your own
ANTHROPIC_API_KEY works too, written as the
models: line that selects it. Say yes to will
your own backend call these tools machine-to-machine? and, on the Local
answer to the sign-in question, init generates the VENDO_SERVICE_KEY step 3
uses — under the Cloud broker you mint that key on the console’s keys page
instead.
The door mints its own principals through an auth preset, so
you need a Next.js app with one wired. Without it init says so and writes
nothing. It writes the composition, the catch-all route, and the origin-root
discovery route. Details: vendo init.
2. Set your origin
The door’s discovery, issuer, and token audience all derive from this one value, so it has to name the origin clients actually reach. Running locally, that is your dev server:3. Connect any client
Whatever origin you set in step 2, plus/api/vendo/mcp. Hosted clients need a
public one.
/api/vendo/mcp/connect for free. Custom and headless
agents take the last tab. The full exchange and key rotation live on
the door reference.
4. Ask for a screen
In the connected client, ask for something you would rather look at than read. The agent callsvendo_make and gets a receipt back: