Connect an MCP client
The Gateway is an MCP server over Streamable HTTP.
Sign in with a key
Create a key in Agents, Connect agent, and send it as a bearer token. This works with every MCP client that can set a header.
JSON settings
Claude Code
Codex
Most clients (Claude Desktop, Cursor, Windsurf and others) read a file like this one:
Sign in with OAuth
A client that supports OAuth for MCP (for example a custom connector in Claude) needs only the address. Give it https://mcp.basement.chat/mcp. The client opens Basement in the browser, you choose the organization and give the connection a name, and Basement gives the client a key of its own.
A connection made this way reads Basement and writes nothing. To let it do more, select an access level for it in Agents, Connected.
The Gateway implements OAuth 2.1 with discovery, dynamic client registration and PKCE:
GET /.well-known/oauth-protected-resourceGET /.well-known/oauth-authorization-serverPOST /oauth/registerPOST /oauth/token
A connection made with OAuth shows in Agents, Connected like any other key, and you revoke it the same way.
Check the connection
Call whoami. It answers the organization, the key’s name and prefix, and the key’s scopes. It works for every key.
What the agent sees
tools/list answers only the tools that the key’s access level allows. A tool that is not in the list answers an error if the agent calls it. See Tools.