{"slug": "create-your-api-and-mcp-server-behind-sign-in-authorization-and-rate-limits-in", "title": "Create your API and MCP server behind sign-in, authorization and rate limits in one prompt", "summary": "APIblaze, a serverless MCP and API gateway, lets developers wrap an existing API with sign-in, per-resource ownership authorization, groups, plain-English rules and rate limits from a single prompt, generating an MCP server URL for agents alongside the proxied API. Running `npx apiblaze create --target <openapi.yaml>` asks two questions, locks resources to their creators, and injects signed identity headers such as x-abz-user-id and x-abz-tenant-id into every call reaching the backend, with an anonymous proxy available to try before claiming it to an account.", "body_md": "You have an API that works. Then the asks start: a customer wants an API key, someone wants to use it from Claude or Cursor, users should only change their own records, and you need rate limits and quotas. Each of those is its own project: auth middleware, OAuth plumbing for MCP clients, authorization rules, a developer portal.\n\n[APIblaze](https://www.apiblaze.com) is a serverless MCP & API gateway with all of that built in. This post walks through what it sets up, with the real commands and output.\n\nOpen Claude Code (or Codex) in your backend's folder and paste:\n\n```\nShow me what APIblaze does using npx apiblaze skills\n```\n\n`npx apiblaze skills` looks at the folder (framework, port, OpenAPI spec) and tells the agent the next step: put your API behind APIblaze, or try it on a sample app first. If you have no OpenAPI spec, the agent writes one.\n\nNo agent? Point it at an OpenAPI spec:\n\n```\nnpx apiblaze create --target https://ninopizzas.com/openapi.yaml\n```\n\nIt asks two questions and prints everything you need. Here's a real run, logged out (trimmed):\n\n```\n? Should only creators of a resource in the API be able to amend that resource?\n❯◉ restaurants — only the person who created a restaurant, or an admin, can view or change it\n ◉ restaurants/{restaurantId}/reservations — only the person who created a reservation, or an admin, can view, change or delete it\n ◉ restaurants/{restaurantId}/tables — only the person who created a table, or an admin, can change or delete it\n? Who is the admin? Their email address (Enter to skip): admin@ninopizzas.com\n✔ API proxy created!\n\n  ✓ https://daringfox2395.tryabz.run/1.0.0/prod — your backend and widget use the API key; people and agents use an APIblaze login (with GitHub)\n  ✓ restaurants, reservations + tables locked to their creator\n\n  MCP URL (for agents):  https://daringfox2395-victorymeadow1963.mcp.tryabz.run/1.0.0/prod\n\n  Try saying to your agent:\n    ✓ \"List the restaurants.\"                       → allowed (lists stay open)\n    ✓ \"Create a reservation, then show it to me.\"   → allowed: you created it\n    ✗ \"Delete a reservation you didn't create.\"     → refused: not yours, and you're not an admin\n    ✓ \"Now do that again as an admin.\"              → allowed: admin@ninopizzas.com is an active admin\n```\n\nNo account is needed to try it: logged out, you get an anonymous proxy you can claim to your account within 30 days.\n\nAn MCP server is there to take actions, and every action needs a person behind it. Every call that reaches your backend carries who's calling, set by the gateway (and stripped if a client tries to send them itself):\n\n```\nPOST /reservations\nx-abz-user-id:   user_8f2k…     # the signed-in person\nx-abz-tenant-id: ninopizza      # their customer space\nx-abz-identity:  eyJhbGciOi…    # the same, signed by the gateway\n```\n\nYour code doesn't change; it can read who's calling from these headers. Lists stay your job: filter collections by tenant and user.\n\nThe ownership rules come from your spec. Groups and plain-English rules go further:\n\n```\n# groups and plain-English rules need a login first: npx apiblaze login\n\n# groups, from the widget or the CLI\nnpx apiblaze group create admin\nnpx apiblaze group create staff\nnpx apiblaze group add-group staff admin      # staff sits inside admin\nnpx apiblaze group add-user maria staff\n\n# one rule, in plain English: tried in shadow mode, then enforced\nnpx apiblaze rule reserv \\\n  \"users see only their own reservations; anyone in admin sees all\"\n```\n\nEvery call is then checked at the proxy, before your backend sees it:\n\n```\nGET /reservations/42   john    his own                  → 200\nGET /reservations/42   alice   not hers, not in admin   → 403\nGET /reservations/42   maria   staff, inside admin      → 200\nnpx apiblaze dev --port 3000\none of your proxies has an openapi.yaml file with a target set to localhost:3000\nTunnel:\nhttps://myapp.abz.run/1.0.0/dev  -> localhost:3000\n```\n\nThe API and its MCP server get public URLs that reach your laptop, with all of the above on, and every call streams to your terminal so you can adapt your responses live.\n\n```\nnpx apiblaze demo\n```\n\nIn about 40 seconds, with nothing but Node 18, a table-booking app for two pizzerias runs on your laptop behind APIblaze.\n\nAsk the assistant to book a table. It goes through the MCP server, as the signed-in user:\n\nNow sign in as Ben and try to cancel Ana's booking. The gateway refuses before the backend sees the call:\n\nEach pizzeria also gets an admin page, with self-serve API keys and a widget to manage users, groups and admins:\n\nThere's no subscription. You pay per request, with every check (sign-in, permissions, rate limits) included, so an API nobody calls costs nothing. If you outgrow it, one command exports your setup to a runnable Kong bundle: config, users, groups and API keys (as hashes, so your callers keep theirs).\n\nAPIblaze is in beta. I'd love to hear where it breaks on your stack.", "url": "https://wpnews.pro/news/create-your-api-and-mcp-server-behind-sign-in-authorization-and-rate-limits-in", "canonical_source": "https://dev.to/julien_jacquet_47c7d6b368/create-your-api-and-mcp-server-behind-sign-in-authorization-and-rate-limits-in-one-prompt-5717", "published_at": "2026-10-08 04:00:51+00:00", "updated_at": "2026-10-08 04:16:58.399870+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "developer-tools", "ai-tools"], "entities": ["APIblaze", "Claude Code", "Codex", "Cursor", "Claude", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/create-your-api-and-mcp-server-behind-sign-in-authorization-and-rate-limits-in", "markdown": "https://wpnews.pro/news/create-your-api-and-mcp-server-behind-sign-in-authorization-and-rate-limits-in.md", "text": "https://wpnews.pro/news/create-your-api-and-mcp-server-behind-sign-in-authorization-and-rate-limits-in.txt", "jsonld": "https://wpnews.pro/news/create-your-api-and-mcp-server-behind-sign-in-authorization-and-rate-limits-in.jsonld"}}