Ocolta
Read your existing categorical document review signals, confidence and indicator counts.
Hosted MCP Server
npx add-mcp 'https://app.ocolta.com/mcp'Installs into Claude Code, Codex, Cursor and more
Documentation
Connect existing summaries to an assistant
Use https://app.ocolta.com/mcp with an OAuth-capable assistant. Approve the connection in the browser where you already have purchased review access, and choose one purchase. The connection lists its recoverable reviews and reads categorical status, priority, confidence and indicator counts. It never starts a review or spends credits. It shares no source documents, personal fields, payment details or free-text report excerpts.
OAuth uses S256 PKCE, one-hour access credentials and rotating credentials with a 30-day maximum connection lifetime. Completed reports still expire after 24 hours. Ocolta retains hashed credential lineage until that connection expires to detect credential reuse; app-client registrations expire after 90 days. IP addresses used for connection rate limits are hashed and the counters expire after a minute. Expired connection records are purged during registration. The assistant may retain summaries it receives. Revoking access prevents future reads and does not erase copies already shared.Manage assistant connections in your purchasing browser. The paid submission API below is a separate capability. Publication in an assistant directory requires its own review; a live endpoint does not imply approval.
Choose the access you grant
In the workspace, load your purchased credits and select one purchase, its exact review tier, a maximum credit spend and an expiry of 7 or 30 days. Create a named connection token and copy it into the trusted tool you intend to use. The token is displayed once. Only a hash is stored by Ocolta.
This grant cannot make purchases, access other purchases, send document-request emails, or open requester or recipient links. Credits remain available in your browser, so balances may change. Previous-account purchases remain eligible under the same stored entitlement rules.
Understand what you share
The chosen integration receives the document you give it and any report it retrieves. Its own terms and retention rules apply to its copies. Share only documents you are authorized to share, and check those terms first. Revoking an Ocolta token blocks later use but does not erase a copy already held by the integration.
Paid document reviews follow Ocolta’s current processing disclosure: OpenRouter and the requested openai/gpt-5.6-terra model, with recoverable reports stored by Ocolta for 24 hours. Deep Review+ also sends allowlisted institution details to research providers. The research privacy guard excludes person and document tokens from queries; automated classification has limits. The API stores no uploaded document. The separate free scan remains local to your browser.
Reviews provide signals and uncertainty for a human reviewer, not proof of authenticity or a consumer report. See privacy and terms.
Submit and recover a review
- Send the token as
Authorization: Bearer oct_…from the integration’s server. Do not forward browser cookies or send an Origin header. - Confirm the user’s document-sharing consent, exact purchased tier and one-credit spend. POST multipart data to
/api/v1/reviewswithfile,consent=true,consentVersion=2026-08-30.openrouter-zdr.v2andanalysisMode=deep-reviewordeep-review-plus. - Set
X-Ocolta-Confirm-Credit: 1and a stable 16–128 characterIdempotency-Key. Keep that key when recovering a lost response. Replays must use the same file bytes, filename, media type, tier and disclosure. - Read status at
/api/v1/reviews/{id}and retrieve the normalized report at/api/v1/reviews/{id}/result. Only the grant that created the review can retrieve it. Ocolta purges recovery reports after 24 hours.
Limits and failed attempts
Uploads are limited to 5 MiB, 25 PDF pages, and images up to 10,000 pixels per side and 40 megapixels. There is one active external review per purchase, up to 50 submissions per purchase in 24 hours, and 60 authenticated requests per grant per minute.
A completed, inconclusive or safety-refused review consumes one credit. The first technical failure permits one manual retry on that credit; a second failed started attempt exhausts it. Exhausted credits count toward the grant’s spending ceiling. Replaying an idempotency key never starts a second review. A retry after a failed operation requires explicit user direction and a new key.
The recoverable report follows the existing browser recovery format. It excludes the deterministic scan and its combined judgment. Report access ends when the token expires or is revoked, the payment is refunded or disputed, or report recovery expires.
Availability
External connections must be enabled by the application operator. A published contract or configured token does not indicate that Muse has reviewed, approved or listed this integration.