aisa skill plus valid CLI auth, or unified MCP with AISA_SEARCH_TOOL, AISA_BATCH_GET_SCHEMA, AISA_BATCH_QUOTE, and AISA_BATCH_USE. Explicit choice or a still-authorized connection wins; do not migrate or reinstall automatically. Do not change unrelated model settings. Describe installs and credentials as in this agent environment.
Default to native remote MCP at https://tools.aisa.one/mcp (Streamable HTTP, OAuth) whenever this client can add that connector — user-local or cloud, with or without a terminal. A working shell is not a reason to choose the CLI.
Use the CLI only when this client has no MCP mechanism at all, for non-interactive automation (CI, cron, scripts) that cannot complete OAuth and already holds a key, or by explicit user choice. These gates and the Node rule below take precedence over any installed aisa skill; the skill covers follow-up operations only.
MCP (default)
Connecthttps://tools.aisa.one/mcp (Streamable HTTP, OAuth). No CLI, npm, npx, or Skill install is required; already-installed guidance may be used. The client owns browser sign-in and tokens. Do not use https://mcp.aisa.one/servers or the default aisa connect web-search server.
Add the connector through this client’s native MCP config, then let the user finish OAuth in the browser. If this client supports MCP but you cannot add the connector from here — unknown capability, sandbox, or permission denied — do not switch to the CLI: ask the user to enable or add the connector, then wait. If the client must reload or start a new session to load the connector, tell the user; verify the four tools afterwards, and do not switch to the CLI meanwhile.
Grok Bot + Plugins: Settings → Plugins → Add → auth if asked → @ attach. If a native custom MCP setup exists, enter that URL and complete OAuth. If neither is available, ask the user to enable or add the connector. grok.com (grok.com/connectors) is a different product.
Then those four tools: search → schema when has_full_schema is false → quote → use. Take IDs and arguments from search/schema; do not invent IDs or prices. Quote does not execute and is not approval. A missing, failed, or partial quote is not free, not a batch total, and not a cap; neither is estimated cost. Re-quote if tools, arguments, or scope change. Stop if the quote or documented maximum exceeds the remaining approved cap.
CLI (only when MCP cannot run here)
Gate: this client has no MCP mechanism, the task is non-interactive automation with an existing key, or the user explicitly chose the CLI. Node.js must already be installed — otherwise stop; use MCP if this client has it, else tell the user Node.js is missing. Do not work around a missing prerequisite or a denied write: no installing Node/npm, no private or isolated runtime, no redirectedHOME.
Node.js missing, or a write denied (e.g. EPERM in a sandbox)? Never work around it yourself. Relay the exact steps for the user to run in their own terminal — if Node.js is missing, install 22.20+ from nodejs.org or their usual package manager (CI: add it to the runner image); then npm install -g @aisa-one/cli and aisa login — then say retry. The CLI and key they install can be reused from here. If they cannot, use MCP or ask which transport they prefer.
--agent to this harness (codex, claude-code, cursor, …). Prefer --global unless the user asked for this repo only. Do not use --all or *. Requires Node.js 22.20.0+ (skills 1.5.25 engines).
If npx skills cannot run and the gate above still holds, read the skill-download section of Agent Quickstart fallbacks before running it.
@aisa-one/cli 0.5.0 or later if present; otherwise install; do not downgrade. CLI may keep Node.js 18+. Read the on-disk skill. Sign in via that skill and aisa login --help. Prove auth with aisa balance. aisa whoami is local only. AISA_API_KEY overrides the stored key; if they conflict, explain both. Never print credentials or send the user to copy a dashboard key. Browser aisa login is the primary credential path for interactive use; headless automation uses a pre-provisioned AISA_API_KEY.
Finish
AIsa is connected. only after OAuth plus those four tools (MCP) oraisa balance (CLI). Metadata or a 401 is not a protected call. A missing connector is not connected. Then continue a named task, or ask What would you like to do first? CLI follows the aisa skill; MCP uses those tools. Setup is not spend approval.
Do not jump to HTTP to bypass missing credentials, exhausted credit, or the same API outage. Do not make paid calls to test availability. Do not extract client-owned MCP OAuth tokens.
Only if CLI and MCP are both unavailable, HTTP works, and a valid AIsa key already exists: read the full direct HTTP section of Agent Quickstart fallbacks (endpoint docs, pricing, approval XML) before a paid proposal, cost approval, or paid request. Extra models, REST, keys, or skills: AIsa docs.