Private stills from a code client are a different job from clicking Generate image in a browser. A developer who already keeps prompts in a repo still has to decide whether the next still is born on a page or inside a tool call. Filmlune exposes both doors, and they do not share the same permission, the same key, or the same moment when the credit number becomes visible.
Catalog access and private generation are not the same permission. Five catalog tools can be read with no key. A still that spends credits needs an active account, a verified email, and an account-bound key. Picking a client before that split is how a ticket ends up with a read-only demo where a generate call was supposed to be.
Two Doors Ask For The Same Still
The job on the ticket is usually small. A service needs a private still, the prompt already exists, and someone has to say which interface runs it. The browser path opens Studio, locks a model and a size, and shows a credit number on Generate image before the click. The client path talks to an MCP endpoint, lists tools, and, only with a key, asks for a private image or video job.
FilmLune describes the second path as MCP access, not a standalone Public API. That sentence changes the design. There is no separate REST surface to wrap, version, and bill on its own. A compatible client uses structured tools on the MCP endpoint. Catalog reads stay public. Cloud generation stays on the account.
Teams lose time when those doors get merged in the README. A prototype that can search cases looks finished, because it returns prompts and revisions. It still cannot spend credits. The afternoon then goes into a key, a verified email, and a second call to check the job, which is work the first demo never showed. That gap is the cost, and it shows up as rework on the ticket rather than as a vague quality complaint.
What The Browser Studio Already Shows
Studio is the place where a person can see the option and the number together. The page tells you to choose a model and settings, adapt the prompt, and generate privately. A request blocked before generation is not charged. Result access and credits follow the review rules, so a still is not automatically a public catalog item just because generation finished.
For a developer deciding whether to automate, that screen is the reference implementation of the charge. You do not have to scrape it. You do have to know which facts it already settles before you reproduce them in a client.
The Quote Sits On Generate Image
The exact quote shown in Studio before launch controls the charge. An unavailable option cannot be launched. Those two rules are the whole pricing contract a caller needs. The site keeps a large table of model options, and video totals depend on the duration you select, but the number that actually bills is the quote on the launch control, not a figure remembered from a README.
If the still comes back unreadable, or the option you wanted was unavailable, the failure is visible next to that quote. You can stop before launch. A client that fires generate_image with a guessed option skips that pause. The rules still apply. The person simply does not see them at the same moment.
History Stays Private After You Generate
Creations stay private by default, and Studio tells you the generation itself is private. When a request is awaiting review, no credits have been charged yet. Generation continues after approval, and the place to look later is History. If that request can no longer continue, no generation credits were charged, and the next step is a new request rather than a retry of the dead one.
That review pause matters on a ticket with a deadline. A job in History marked awaiting review is not a file you can attach. Treating it as done publishes nothing and also double-submits if someone generates again out of impatience. The private default is the other half: a successful still is not a catalog publish.
What An MCP Client Is Allowed To Call
A compatible client connects to the Streamable HTTP endpoint, or runs the local stdio server. The remote side exposes five public catalog tools plus three account-bound generation tools. Protocols named on the page are 2025-11-25 and 2026-07-28. Catalog reads need no key. Generation requires an eligible account-bound MCP access key, and the account needs a verified email. Until that email is verified, catalog access remains available and generation stays blocked.
The local stdio server is the easy place to get this wrong. It offers the five read-only tools with no account, no cloud generation, and no credit access. A process that works on a laptop over stdio has not proven that generate_image will run, because that binary path cannot spend credits at all.
Five Public Reads Need No Key
The public tools are search_cases, get_case, list_models, list_taxonomy, and get_changes. Search returns reusable cases with deterministic pagination. get_case reads one exact revision, its provenance, and its reuse rights. list_models lists models actually present in the filtered catalog. list_taxonomy browses media, model, use-case, and style axes. get_changes tracks additions and removals without handing removed content back.
An MCP response keeps the case revision, provenance, rights, and canonical URL. The intended next step on the page is to use the library to understand the prompt, then adapt the method in Studio. Reading a case is not a license to write the catalog. The generated catalog has no write path. Record-level rights and the separate content license govern prompt use. Case media and third-party materials stay excluded.
Store the revision you got from get_case, not a prompt string copied into a comment. get_changes can tell the client what was added or removed without returning the removed body, so a sync job that re-fetches every case on a timer will keep serving a revision the catalog has already dropped. list_models is the filtered catalog, not a promise that every name you remember can be launched. If the option is not available, Studio will not launch it, and a client should treat that as a stop rather than a retry with a nearby model name.
Here an AI image generator call is the authenticated trio, not the public five. generate_image and generate_video create an owner-private job. check_generation reads that job. The call follows the site's safety and credit controls. It cannot edit catalog content, and it cannot publish the catalog. FilmLune is still the system of record. The client is a caller.
A Short Table For The Ticket
Compare the two doors on the questions a ticket actually asks. The rows are permissions and charge visibility, not a ranking of image quality.
| Question | Browser Studio | MCP client |
|---|---|---|
| Read a public case | Open the prompt on the case | search_cases and get_case, no key |
| Make a private still | Generate image after the quote | generate_image with an access key, then check_generation |
| Who may generate | A signed-in session | Active account, verified email, account-bound key |
| What the call must not do | A blocked pre-generation request is not charged | No catalog write, and no publish of catalog content |
Read the table as a gate, not as a feature list. If the ticket only needs a prompt and its revision, stop at the public tools. If the ticket needs pixels, the key and the verified email are part of the task, and the local stdio server will not supply them.
Where MCP Still Needs A Person
MCP still needs a person because the call does not review the still. This is client access, not a standalone Public API, and the local stdio server cannot generate in the cloud or spend credits. An authenticated call creates a private job only. It cannot edit or publish catalog content. Someone still has to look at the still before it ships.
Credit Rules That Travel With The Call
MCP generation uses the same prices and credit rules as the website. Welcome and daily credits apply only to GPT Image 2 at 1K Standard. A generate_image call aimed at another model, or at another size, is outside that allowance even when the key is valid. The amounts and the daily reset belong to the account rules. They are not a second price list invented by the client.

The quote that controls the charge is still the one Studio shows before launch. An unavailable option cannot be launched there, and the same rule travels with the account. A client that caches yesterday's number can disagree with today's quote. When that happens, the Studio quote wins. FilmLune does not ask the caller to keep a private tariff.
Blocked and unfinished jobs have their own no-charge paths. A request blocked before generation is not charged. A request that can no longer continue charges no generation credits, and it has to be submitted again. check_generation is how a client learns which of those states it is in. Polling a dead job and then launching a duplicate is how the credit ledger grows without a new creative decision.
A health check that only calls list_models will stay green on an account whose email is not verified yet. Catalog access remains available in that state, and generation does not. The ticket looks done because the client can list the public five, while generate_image is still refused. Put the verified-email check next to the key check, or the first real still fails in production after the demo already passed.
Which Interface Belongs On The Ticket
Studio fits the person who needs to see the quote, the option, and the private result in one place before a still is allowed to leave the machine. FilmLune is a reasonable place to do that job when the prompt is still being adapted and the charge has to be visible before launch.
An MCP client fits a codebase that already speaks the protocol, has a verified account, and can store an access key. It is a poor fit when the only environment available is the local read-only server, or when the ticket assumes a Public API with its own price list. Catalog search is not generation. A private job is not a publish.
Put the door on the ticket before the call. If the still must be seen and priced by a person, open Studio. If the client is allowed to generate, give it the key, then check the job, and still have someone look at the file.
