Developer setup

Your account page.
A fair way out.

Start with the free embed or AI connector. Subscription changes require a connection to the billing provider that owns the subscription. The current verified adapter is Stripe sandbox; a Shopify subscription-app adapter is still required for Shopify billing.

Hosted cancellation

Your backend authenticates the customer and looks up their subscription. It creates a short-lived link with a private server key, then redirects that customer to it. Never trust a customer or subscription ID supplied by the browser.

POST https://usefatcat.com/api/v1/sessions
Authorization: Bearer gate_sec_…
Content-Type: application/json

{"customer_id":"cus_…","subscription_id":"sub_…","intent_kind":"cancel"}

The response contains url and expires_at. Use the returned URL for the signed-in customer’s cancel action. It expires in 30 minutes. A shared public customer-ID URL cannot authorize billing.

Embed script · Free to connect

Set your exact HTTPS shop origin in Brand settings. Load this script once; it inherits the shop’s font and uses your approved conversation style. It contains no cat and no private key.

<script src="https://usefatcat.com/fatcat.js" defer></script>

Keep a working normal cancellation URL as a fallback. Your same-origin session endpoint must verify the login and CSRF protection, derive the IDs server-side, call the session API above, and return its response.

<a href="/account/cancel" data-fat-cat="/api/cancel-session">
  Cancel subscription
</a>

If the script or session service fails, the existing cancellation link still works. The widget uses a short-lived customer token in memory, never a merchant key. Cross-origin requests are restricted to the saved shop origin.

React

Use the same script and call the widget after your backend creates a session:

async function cancelSubscription() {
  const response = await fetch('/api/cancel-session', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: '{}'
  });
  if (!response.ok) {
    window.location.assign('/account/cancel');
    return;
  }
  const session = await response.json();
  if (!window.FatCat) {
    window.location.assign('/account/cancel');
    return;
  }
  await window.FatCat.openCancellation({
    sessionUrl: session.url,
    fallbackUrl: '/account/cancel'
  });
}

<button onClick={cancelSubscription}>Cancel subscription</button>

The reusable TypeScript component is included in sdk/FatCatCancellation.tsx in the repository. Embed, Stripe and AI access have no monthly fee. Verified saves alone are eligible for a success fee.

ChatGPT / Claude connector

https://usefatcat.com/mcp

Paste this URL into remote connector settings and use OAuth. The installation page shows whether sign-in activation is ready. Your workspace approval permits merchant reads and previews only.

get_workspace_rules, preview_retention_negotiation, list_subscriptions, get_retention_options and get_learning_status share Greedy Cat’s policy engine. For a counteroffer, return next_state as previous. Preview state never grants billing authority.

The actual customer still confirms exact terms through the authenticated hosted page or embed. Revoke your AI connection in Integrations. Never send a server key to a chat.

Customer context and offers

Optional numeric usage context helps the decision engine. Pricing and approved offer terms come from the policy layer, never from the conversation model. A customer reviews exact terms before accepting. “Continue cancelling” stays visible.

For a premium-feature trial, configure a custom benefit with exact terms, cost, minimum tenure and included feature IDs. Send blocked_feature_keys in the authenticated session context, derived from your own product events. A matching ID makes that existing benefit eligible; customer chat cannot invent an entitlement.

"customer_context": {
  "days_since_activity": 4,
  "previous_discounts": 0,
  "blocked_feature_keys": ["advanced_exports"]
}

Your team must deliver a confirmed benefit request and record its fulfillment. Fat Cat does not automatically grant premium access, purchase third-party subscriptions or issue cash payouts. Do not send names, browsing histories or scraped personal profiles as context.

Launch boundaries

Shopify OAuth credentials, subscription-app compatibility, live provider verification must be completed before installation is advertised as live. Fee collection stays off until merchant payment authorization is connected. The merchant MCP connector uses the same decision engine; it cannot impersonate a shopper or confirm billing for them.

Open integrations →