Connect MCP accounts
Reuse a declared CLI server login or configure client credentials for the built-in harness.
Choose a form
Section titled “Choose a form”Set oauth on a declared HTTP MCP server to use a saved login or client credentials. This option replaces bearerTokenVariable and any Authorization header; choose the form supported by your harness.
| Form | Harnesses | Token source |
|---|---|---|
oauth: "login" | Claude Code, Codex, Kimi Code | The CLI’s own MCP login, made once on the host |
oauth: { client… } | Built-in harness | A client credentials grant requested in the sandbox |
| Neither | Copilot CLI, Antigravity | Use bearerTokenVariable with a token you provide |
A harness that cannot use the declared form fails when the agent is composed.
Reuse a CLI login
Section titled “Reuse a CLI login”Log in on the host with the same server name and URL as your declaration.
Then declare oauth: "login".
| CLI | Host login | Host file (relocated by) |
|---|---|---|
| Claude Code | claude mcp add --transport http linear https://mcp.linear.app/mcp, then claude mcp login linear | ~/.claude/.credentials.json (CLAUDE_CONFIG_DIR) |
| Codex | Set mcp_oauth_credentials_store = "file" in ~/.codex/config.toml, then codex mcp login linear | ~/.codex/.credentials.json (CODEX_HOME) |
| Kimi Code | Add the server to ~/.kimi-code/mcp.json, then authenticate it in a kimi session | ~/.kimi-code/credentials/mcp/ (KIMI_CODE_HOME) |
Before the agent starts, Outpost copies only the matching server entries into the private sandbox home. Your other logins, including the CLI account itself, are not copied by this option. A missing login fails with the host command to run.
With createLocalSandboxProvider(), nothing is copied: the CLI reads your home directly.
Request tokens with client credentials
Section titled “Request tokens with client credentials”For machine-to-machine servers in the built-in harness, name the variables that hold the client ID and secret.
Declare both variables on the sandbox provider or in .outpost/.env (Environment variables). Without scopes, the bridge requests the scope named in the server’s 401 challenge, if any.
The HTTP bridge in the sandbox obtains the token itself, so the secret stays there and outbound rules apply to the token requests.
Limits
Section titled “Limits”oauthis for HTTP servers only and cannot be combined withbearerTokenVariableor anAuthorizationheader.- The built-in harness refuses
"login"; CLI harnesses refuse client credentials. - Client credentials support neither
private_key_jwt, refresh tokens nor interactive authorization. - Outpost never reads a system keychain: a CLI that stores its MCP login there has nothing to copy.
API: McpHttpServer · McpClientCredentials · McpServers.