MCP servers: connect AI coding assistants to your tools
AI coding assistants like Cursor, Codex, and Claude are powerful on their own, but they become significantly more useful when they can interact with your actual services — querying data, creating resources, and running operations without you switching context. That is exactly what MCP servers enable.
MCP adoption is faster when teams standardize key management, tool permissions, and assistant configuration.
The fastest path to value is read-only setup first, then controlled write access once workflows are proven.
What is MCP?
The Model Context Protocol (MCP) is an open standard that lets AI assistants call external tools over a structured interface. Instead of the assistant guessing or asking you to copy-paste, it can directly invoke a tool — like "list all apps" or "create a link" — and get a real response from your service.
An MCP server exposes a set of tools (think of them as typed API endpoints) that the assistant can discover and call. Each tool has a name, a description, an input schema, and returns structured output. The assistant sees the tool list, decides which one fits your request, fills in the parameters, and calls it.
How it works
- Discovery — the assistant connects to the MCP server and calls
tools/listto learn what tools are available. - Planning — when you ask a question or give an instruction, the assistant picks the right tool and fills in the arguments.
- Execution — the assistant calls
tools/callwith the tool name and arguments. The server processes the request and returns a result. - Response — the assistant reads the result and presents it to you in natural language.
Configuring MCP servers in Cursor
Cursor uses a .cursor/mcp.json file at the root of your workspace (or in your home directory for global config).
{
"mcpServers": {
"my-service": {
"url": "https://example.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}
The url field points to the MCP endpoint. The headers object is sent with every request — use it for authentication. After saving the file, reload Cursor (or restart it) so the MCP server is picked up.
Configuring MCP servers in Codex
Codex reads MCP server configuration from ~/.codex/config.toml.
[mcp_servers."my-service"]
type = "url"
url = "https://example.com/mcp"
[mcp_servers."my-service".headers]
Authorization = "Bearer YOUR_API_KEY"
Restart Codex after editing the config.
Configuring MCP servers in Claude
Claude Desktop reads MCP configuration from its settings file. On macOS this is ~/Library/Application Support/Claude/claude_desktop_config.json.
{
"mcpServers": {
"my-service": {
"url": "https://example.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}
Restart Claude Desktop after saving changes. The server will appear in the tool list when you start a new conversation.
LinkMe MCP server
LinkMe provides a deployed MCP server at https://li-nk.me/mcp. It lets you explore apps, projects, and environments, and manage approved link workflows directly from your AI assistant.
The endpoint uses stateless Streamable HTTP and MCP protocol version 2025-11-25. It does not retain an MCP session between requests, so it can safely run behind a load balancer. Clients should use their MCP client's normal HTTP transport; there is no MCP-Session-Id to configure.
Getting an MCP key
- Sign in to the LinkMe portal.
- Go to the Team page.
- In the MCP Keys section, generate a new key.
Keys can be personal (access your own apps) or team-scoped (access all apps in a team). MCP keys are available on the Indie plan and above.
Each key has can_read and can_write capabilities. Start with read-only and enable writes only when needed.
Cursor setup
Add this to .cursor/mcp.json in your project root:
{
"mcpServers": {
"linkme": {
"url": "https://li-nk.me/mcp",
"headers": {
"Authorization": "Bearer tk_YOUR_KEY"
}
}
}
}
Reload Cursor and the LinkMe tools will appear in the MCP panel.
Codex setup
Add this to ~/.codex/config.toml:
[mcp_servers."linkme"]
type = "url"
url = "https://li-nk.me/mcp"
[mcp_servers."linkme".headers]
Authorization = "Bearer tk_YOUR_KEY"
Restart Codex to pick up the new server.
Claude setup
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"linkme": {
"url": "https://li-nk.me/mcp",
"headers": {
"Authorization": "Bearer tk_YOUR_KEY"
}
}
}
}
Restart Claude Desktop to pick up the new server.
Available tools
Once connected, your assistant can use these tools:
App and team read tools
| Tool | What it does |
|---|---|
health.get | Check if the LinkMe API is healthy. |
apps.list | List all apps you own or have access to (personal keys). |
apps.listByTeam | List all apps in your team (team-scoped keys — team ID is auto-filled). |
teams.get | Get details about your team (team-scoped keys — team ID is auto-filled). |
apps.get | Get details for a specific app by ID. |
links.listByApp | List all links for a specific app. |
links.getInsights | Get click analytics and insights for a specific link. |
links.getDetails | Get full details for a link including metadata and configuration. |
Workspace tools (signed-in sessions only)
Workspace setup changes the deployment topology, so these tools require a signed-in portal session. Personal and team MCP keys cannot enumerate or mutate projects or environments.
| Tool | What it does |
|---|---|
workspace.getHierarchy | Show the projects, environments, and targets visible to you. |
projects.list / projects.get | List projects or inspect a project and its targets. |
projects.listImportableApps | Find apps that can be moved into a project. |
environments.get | Inspect an environment, its targets, bindings, domains, and fallback origins. |
Workspace setup and app moves (writes enabled + signed-in session)
| Tool | What it does |
|---|---|
projects.create | Create a personal project or a project in an accessible team. |
environments.create | Add an environment such as development, staging, or production. |
surfaces.create | Add a routable product surface within a project. |
environments.addFallbackOrigin | Add an HTTPS fallback origin to an environment. |
projects.setBinding | Bind a project surface to an app target in one of the project environments. |
environments.setBinding | Bind an app target to an environment and surface. |
apps.previewMove | Validate an app move without making changes. |
apps.move | Move an app into the selected project, environment, and surface. |
Write tools (require can_write on the key)
| Tool | What it does |
|---|---|
links.create | Create a new link in an app. |
links.update | Update an existing link's configuration. |
The same MCP surface also covers the portal's Edge-backed management actions: app creation/update/deletion, custom domains, link deletion and stats reset, assets, UTM presets, app API keys, webhooks, dashboard analytics, team management, workspace setup, and user-owned public short links. These actions use the same session ownership, team membership, app-key capability, and write-gate checks as the corresponding portal requests. Billing, account deletion, authentication, and portal-only superadmin user management are intentionally not MCP tools.
System administration (superadmins only)
apps.restore restores a soft-deleted app, while apps.reassignOwner changes an
app's owner. Both require a signed-in superadmin session and server-side writes
to be enabled. They are not available to owners, team members, or any API key.
What you can ask
Here are examples of natural language requests your assistant will handle using LinkMe MCP:
Listing and exploring:
- "What apps do I have?"
- "Show me all links for app app_abc123"
- "Get insights for link link_xyz789"
- "Is the LinkMe API healthy?"
Creating and managing (write-enabled keys only):
- "Create a new link in app app_abc123 pointing to https://example.com"
- "Update link link_xyz789 to redirect to https://new-url.com"
Organizing a workspace (signed-in session with writes enabled):
- "Show my workspace hierarchy"
- "Create a staging environment in the Mobile project"
- "Preview moving the iOS app into production before making the change"
- "Bind the customer app to the customer surface in staging"
Team context (team-scoped keys):
- "What apps does my team have?"
- "Show me the team details"
- "List links for the team's marketing app"
The assistant automatically uses the right tool based on your key type — you do not need to specify team IDs or worry about which endpoint to call.
Security
LinkMe MCP enforces the same security boundaries as the REST API:
- MCP can only call explicitly allowlisted endpoints.
- Your key's
can_read/can_writecapabilities are enforced on every call. - App-key scoped requests must match the key's app ID.
- Team membership is enforced by the REST layer — MCP cannot bypass it.
- Project and environment tools are session-only and remain constrained to projects the user owns or can access through a team.
- Ownership reassignment is limited to
superadminsessions. - Write tools are disabled by default on the server.
- Internal endpoints (
/internal/*) are never accessible.
For browser-based clients, configure MCP_ALLOWED_ORIGINS with each permitted
origin. Requests with an unapproved Origin header are rejected.
For the full security model, see the MCP Security & Access Model documentation.
Do not commit real API keys to version control. Use placeholder values in checked-in config files and override locally, or add .cursor/mcp.json to .gitignore.