Skip to main content
The MCP server accepts two kinds of credentials. The one you pick decides who the assistant acts as. In Claude Code, Codex, Cursor, Gemini CLI, VS Code, and Windsurf, leave the key out of the config to sign in with OAuth. Put the key in to use the API key. Both expose the same tools.

OAuth, scoped to you

The assistant acts as the person who approved the connection. Notes and comments it adds are signed with that person’s name. It can reach every feature request in the workspaces you approve, within the scopes you tick below. Use OAuth when a person drives the assistant. For the steps, see Connect agent.

What you approve

If you leave a scope unticked, a tool that needs it is refused with a message that names the scope. For example, a read-only connection can search feature requests but cannot create one, move one, or post a comment. One OAuth connection can reach several workspaces. Name the workspace in your prompt, or ask the assistant to list the workspaces it can reach. Every tool takes an optional workspace argument for this.

API key, scoped to the workspace

An API key is not tied to a person. Every tool call reaches the whole workspace with every scope. Notes and comments it adds are signed with the name of the workspace’s oldest team member. Use a key for automation. Use OAuth when a person drives the assistant, so their notes carry their name. The key is the same one the REST API uses. Put it in the server entry of the assistant’s config file:
For the full config of each client, see Connect agent. Learn how to generate your API key.
A key belongs to one workspace. To reach two workspaces, add the server twice, with a different key and a different server name in each entry.
An API key gives access to every feature request in the workspace. Treat it like a password: keep it out of shared config files and commits, and revoke it if it leaks.

How the three interfaces authenticate