Desktop clients: multiple services in one connection

Use standard OAuth sign-in and explicitly select each service, tool, prompt, resource and subscription. Write requests are off by default and still require individual approval when enabled. Current group permissions and each service grant constrain calls; new tools never expand existing grants. Revoke one service or the whole connection in the portal.

mcpbridge login --native --server https://hub.example.com/mcp --profile work
mcpbridge connect --profile work

Use this flow with a local browser. Administrators preregister native MCP client callbacks under Operations → OAuth clients. Clients use PKCE and standard Bearer credentials without a custom grant header. Headless Agents retain device link authorization, with one service per pairing; existing single-service entries remain available.

For remote or headless Agents, use link authorization: sign in and choose access on one page, or use --interactive-auth for authentication tools. The existing setup flow below remains available.

Choose your AI client

ClientConfigurationSteps
CodexConvert the generated connection details to TOML.Connect Codex →
Claude CodeAdd a local connection with claude mcp add.Connect Claude Code →
VS CodeSelect format 2 in setup and merge it into mcp.json.Connect VS Code →
Other stdio MCP clientsEnter command, args, and env.Continue below.

Understand the generated configuration

{
  "mcpServers": {
    "work-projects": {
      "command": "/absolute/path/to/mcpbridge",
      "args": ["connect", "--profile", "work", "--client", "ci_example"],
      "env": { "MCPHUB_HOME": "/Users/you/.mcphub" }
    }
  }
}

This example shows the structure. command is the actual executable path; args select your profile and real entry ID; MCPHUB_HOME points to your private credentials directory. Use setup's output and replace every example value.

Escape backslashes in Windows JSON paths, for example C:\\Tools\\mcpbridge\\mcpbridge.exe. Merge existing objects instead of adding a second top-level key with the same name.

Configure another client

  1. Confirm that the client can launch a local stdio MCP process.
  2. Choose format 1, generic JSON, in setup.
  3. For mcpServers-based clients, merge the generated entry. For form-based clients, enter command, args, and environment variables separately.
  4. Reload the MCP connection and check that tools are visible.
  5. Run doctor with the same profile and entry ID.
Use the connector for client authorizationThis guide uses mcpbridge connect --client …. Adding an HTTP URL alone may not meet your company's authorization requirements. Use an approach your administrator explicitly supports.

Can I share my configuration?

Generated configuration contains no token, but includes local paths and an entry ID bound to your authorization. Other employees should run setup themselves. Sharing configuration does not sign them in or make it usable on another computer.

Create a separate entry for each AI client so you can revoke it independently. Authorize each service separately.