Skip to navigation

Connect an MCP client

The address, the two ways to sign in, and settings for common clients.
View as Markdown

The Gateway is an MCP server over Streamable HTTP.

Addresshttps://mcp.basement.chat/mcp
TransportStreamable HTTP (JSON-RPC over POST)
Protocol versions2025-06-18, 2025-03-26, 2024-11-05
Sign inA key (Authorization: Bearer bsmt_...), or OAuth 2.1

Sign in with a key

Create a key in Agents, Connect agent, and send it as a bearer token. This works with every MCP client that can set a header.

Most clients (Claude Desktop, Cursor, Windsurf and others) read a file like this one:

{
"mcpServers": {
"basement": {
"url": "https://mcp.basement.chat/mcp",
"headers": { "Authorization": "Bearer bsmt_your_key" }
}
}
}

Sign in with OAuth

A client that supports OAuth for MCP (for example a custom connector in Claude) needs only the address. Give it https://mcp.basement.chat/mcp. The client opens Basement in the browser, you choose the organization and give the connection a name, and Basement gives the client a key of its own.

A connection made this way reads Basement and writes nothing. To let it do more, select an access level for it in Agents, Connected.

The Gateway implements OAuth 2.1 with discovery, dynamic client registration and PKCE:

  • GET /.well-known/oauth-protected-resource
  • GET /.well-known/oauth-authorization-server
  • POST /oauth/register
  • POST /oauth/token

A connection made with OAuth shows in Agents, Connected like any other key, and you revoke it the same way.

Check the connection

Call whoami. It answers the organization, the key’s name and prefix, and the key’s scopes. It works for every key.

{
"orgId": "…",
"orgName": "Acme Robotics",
"keyName": "Claude for call prep",
"keyPrefix": "bsmt_4UMl",
"scopes": ["gateway:read", "tools:use"],
"expiresAt": null
}

What the agent sees

tools/list answers only the tools that the key’s access level allows. A tool that is not in the list answers an error if the agent calls it. See Tools.