Credential Access
High
- Category
- Privilege Escalation
- Content
1. Open [Chiho.ai](https://chiho.ai/signup). 2. Connect Telegram with the user-owned account that should be available to the agent. 3. Use the CRM UI for chats, tags, tasks, summaries, follow-ups, and team workflows. 4. Mint an Agent Access token from `https://chiho.ai/profile/agent-access`. 5. Copy the MCP endpoint shown on Agent Access and configure OpenClaw or another compatible client to send `Authorization: Bearer <CHIHO_AGENT_TOKEN>` with every MCP request. Claude Code supports this hosted bearer-token flow through `claude mcp add --transport http ... --header ...`. Claude web, Claude Desktop, and Cowork remote custom connectors require OAuth for authenticated hosted servers and cannot use Chiho Agent Access tokens yet. Never place a Chiho token in a connector URL or OAuth credential field.
- Confidence
- 90% confidence
- Finding
- Access token
