Skip to main content
The remote MCP endpoint is:
Version 0.1.5 supports SDK v1 and SDK v2 clients, including legacy 2025-11-25 and modern 2026-07-28 protocol revisions. Workspace OAuth tokens retain the read-only communicate_list_agents tool. Explicitly MCP-bound account credentials expose the registered management tools allowed by their live scopes.

Create an MCP management credential

Use the CLI bootstrap workflow with a private input file containing verified email/password proof, a credential name, the scopes your workflow needs, and this explicit audience:
This fragment supplies the audience and scopes; include the remaining required bootstrap fields from command help. Store the one-time token in a protected output file or secret manager, then configure it as COMMUNICATE_MCP_TOKEN. Account credentials expire within 24 hours and cannot outlive their issuer session. Each tool declares its input/output schema. Missing scopes remove tools from discovery; native membership, role, agent access and entitlement checks still apply. Writes are never automatically retried. Source file uploads take { "file": { "name": "guide.txt", "base64": "..." } } plus workspace/agent IDs, with a 10 MB decoded limit. The server does not read filesystem paths. REST-bound ca_ credentials and REST OAuth tokens cannot call MCP. Existing ck_ workspace secrets never gain account management permissions automatically. Coverage remains partial; billing, inbox/prospect reply and other unfinished workflows are not established by this increment.

Legacy read-only workspace OAuth

Create an API key with agents:read, then exchange its client ID and one-time ck_ secret for a token bound to the MCP resource.
The token expires after one hour. Request a new token before reconnecting after expiry.

Configure your client

Use Streamable HTTP and send the token as a bearer credential:
For Codex, use the equivalent environment-backed bearer token setting:
Do not place the client secret or bearer token directly in a committed configuration file. The endpoint does not accept long-lived ck_ secrets.

OAuth discovery

MCP clients can discover the authentication contract from:
Workspace OAuth MCP tokens accept only agents:read; this restriction does not apply to explicitly scoped MCP account credentials. Use a separate REST token with chat:write for agent conversations.