cd /news/ai-agents/create-your-api-and-mcp-server-behin… Β· home β€Ί topics β€Ί ai-agents β€Ί article
[ARTICLE Β· art-147313] src=dev.to β†— pub= topic=ai-agents verified=true sentiment=↑ positive

Create your API and MCP server behind sign-in, authorization and rate limits in one prompt

APIblaze, a serverless MCP and API gateway, lets developers wrap an existing API with sign-in, per-resource ownership authorization, groups, plain-English rules and rate limits from a single prompt, generating an MCP server URL for agents alongside the proxied API. Running `npx apiblaze create --target <openapi.yaml>` asks two questions, locks resources to their creators, and injects signed identity headers such as x-abz-user-id and x-abz-tenant-id into every call reaching the backend, with an anonymous proxy available to try before claiming it to an account.

by read4 min views3 publishedOct 8, 2026

You have an API that works. Then the asks start: a customer wants an API key, someone wants to use it from Claude or Cursor, users should only change their own records, and you need rate limits and quotas. Each of those is its own project: auth middleware, OAuth plumbing for MCP clients, authorization rules, a developer portal.

APIblaze is a serverless MCP & API gateway with all of that built in. This post walks through what it sets up, with the real commands and output.

Open Claude Code (or Codex) in your backend's folder and paste:

Show me what APIblaze does using npx apiblaze skills

npx apiblaze skills looks at the folder (framework, port, OpenAPI spec) and tells the agent the next step: put your API behind APIblaze, or try it on a sample app first. If you have no OpenAPI spec, the agent writes one.

No agent? Point it at an OpenAPI spec:

npx apiblaze create --target https://ninopizzas.com/openapi.yaml

It asks two questions and prints everything you need. Here's a real run, logged out (trimmed):

? Should only creators of a resource in the API be able to amend that resource?
❯◉ restaurants β€” only the person who created a restaurant, or an admin, can view or change it
 β—‰ restaurants/{restaurantId}/reservations β€” only the person who created a reservation, or an admin, can view, change or delete it
 β—‰ restaurants/{restaurantId}/tables β€” only the person who created a table, or an admin, can change or delete it
? Who is the admin? Their email address (Enter to skip): admin@ninopizzas.com
βœ” API proxy created!

  βœ“ https://daringfox2395.tryabz.run/1.0.0/prod β€” your backend and widget use the API key; people and agents use an APIblaze login (with GitHub)
  βœ“ restaurants, reservations + tables locked to their creator

  MCP URL (for agents):  https://daringfox2395-victorymeadow1963.mcp.tryabz.run/1.0.0/prod

  Try saying to your agent:
    βœ“ "List the restaurants."                       β†’ allowed (lists stay open)
    βœ“ "Create a reservation, then show it to me."   β†’ allowed: you created it
    βœ— "Delete a reservation you didn't create."     β†’ refused: not yours, and you're not an admin
    βœ“ "Now do that again as an admin."              β†’ allowed: admin@ninopizzas.com is an active admin

No account is needed to try it: logged out, you get an anonymous proxy you can claim to your account within 30 days.

An MCP server is there to take actions, and every action needs a person behind it. Every call that reaches your backend carries who's calling, set by the gateway (and stripped if a client tries to send them itself):

POST /reservations
x-abz-user-id:   user_8f2k…     # the signed-in person
x-abz-tenant-id: ninopizza      # their customer space
x-abz-identity:  eyJhbGciOi…    # the same, signed by the gateway

Your code doesn't change; it can read who's calling from these headers. Lists stay your job: filter collections by tenant and user.

The ownership rules come from your spec. Groups and plain-English rules go further:


npx apiblaze group create admin
npx apiblaze group create staff
npx apiblaze group add-group staff admin      # staff sits inside admin
npx apiblaze group add-user maria staff

npx apiblaze rule reserv \
  "users see only their own reservations; anyone in admin sees all"

Every call is then checked at the proxy, before your backend sees it:

GET /reservations/42   john    his own                  β†’ 200
GET /reservations/42   alice   not hers, not in admin   β†’ 403
GET /reservations/42   maria   staff, inside admin      β†’ 200
npx apiblaze dev --port 3000
one of your proxies has an openapi.yaml file with a target set to localhost:3000
Tunnel:
https://myapp.abz.run/1.0.0/dev  -> localhost:3000

The API and its MCP server get public URLs that reach your laptop, with all of the above on, and every call streams to your terminal so you can adapt your responses live.

npx apiblaze demo

In about 40 seconds, with nothing but Node 18, a table-booking app for two pizzerias runs on your laptop behind APIblaze.

Ask the assistant to book a table. It goes through the MCP server, as the signed-in user:

Now sign in as Ben and try to cancel Ana's booking. The gateway refuses before the backend sees the call:

Each pizzeria also gets an admin page, with self-serve API keys and a widget to manage users, groups and admins:

There's no subscription. You pay per request, with every check (sign-in, permissions, rate limits) included, so an API nobody calls costs nothing. If you outgrow it, one command exports your setup to a runnable Kong bundle: config, users, groups and API keys (as hashes, so your callers keep theirs).

APIblaze is in beta. I'd love to hear where it breaks on your stack.

── more in #ai-agents 4 stories Β· sorted by recency
── more on @apiblaze 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain β€” perfect for shipping the agent you just read about.

$git push zahid main
β†’ Live at https://your-agent.zahid.host βœ“
Get free account β†’ Pricing
from €0/mo Β· no card required
LIVE [news/create-your-api-and-…] indexed:0 read:4min 2026-10-08 Β· β€”