MCP-Server
Motir exposes a Model Context Protocol server — one streamable-HTTP endpoint that agents and the CLI call to read and drive the project-management core. It is the same surface the hosted agents use to execute a plan. Adding it to Claude takes one sign-in and no token; any other client, or a pipeline, connects with a token in three steps.
Add Motir to Claude
You sign in with your Motir account, pick one workspace and approve what Claude may do there. Nothing is copied or pasted — there is no token to mint or keep safe.
claude.ai
- Open Customize → Connectors.
- Click “+”, then Add custom connector, and paste the server URL below. Under OAuth client, choose Use Claude’s published identity — claude.ai marks it Detected, because Motir supports it. Leave the OAuth client ID and secret empty — Motir needs neither.
- Click Add, then Connect. Claude sends you to app.motir.co to sign in and approve.
Remote MCP server URL
https://app.motir.co/api/mcp
On a Team or Enterprise plan an Owner adds the connector once, under Organization settings → Connectors → Add → Custom → Web, and each member then clicks Connect under Customize → Connectors with their own Motir account. · Anthropic’s claude.ai documentation · steps checked 2026-10-02
Claude desktop app
- If you already connected Motir on claude.ai, there is nothing to add: a connected connector is available in your conversations on the web, the desktop app and mobile.
- To add it from the desktop app instead, select Customize in the sidebar, then Connectors, and follow the claude.ai steps with the same URL.
- The Motir sign-in page opens in your browser; approve there and return to the app.
Remote MCP server URL
https://app.motir.co/api/mcp
This is a remote connector, not a local desktop extension: Claude reaches Motir from Anthropic’s cloud, so nothing is installed on your machine. · Anthropic’s Claude desktop app documentation · steps checked 2026-10-01
Claude Code
- Add the server with the command below — no header and no token.
- In Claude Code, run /mcp, select motir and follow the sign-in in your browser.
your terminal
claude mcp add --transport http motir https://app.motir.co/api/mcp
If you signed Claude Code in with your Claude account, a connector you connected on claude.ai is already available there. The Motir plugin for Claude Code brings this server with it, beside the skills. · Anthropic’s Claude Code documentation · steps checked 2026-10-01
What you approve, and how to take it back
The sign-in page on Motir names the app that is asking, has you choose one workspace, and lists the permissions it wants. Claude then acts as you in that workspace, within what you approved — never beyond what your own role allows.
When claude.ai connects with Claude’s published identity, Motir checks that claude.ai publishes it, and shows claude.ai as a verified domain on the sign-in page and in Connected apps. Any other MCP client that registers itself reads Unverified: the name it shows is one it chose, and Motir cannot check it.
Claude asks before it uses a tool that changes anything: every tool says whether it only reads, writes or deletes, and MCP-Tools shows which is which. Want the plugin for Claude Code instead? It brings this server with it — Skills.
Every app you connect is listed under Connected apps, on Settings → Account → Tokens in Motir, with its workspace, permissions and when it was last used. Revoke ends its access at its next request.
Other clients and CI: use a token
Choose this route for a client without OAuth sign-in, a headless agent, or a CI pipeline. It is the same server; a personal access token stands in for the sign-in.
This server, or the REST API?
Both speak to the same data and take the same credential. They are built for different consumers, and the difference that matters is what each promises about changing under you.
| MCP-Server | API-Referenz | |
|---|---|---|
| Endpoint | POST /api/mcp | /api/v1/… |
| Built for | An agent you control — it reads tool descriptions at run time. | A client you ship — code written once against a fixed shape. |
| Stability | Expected to change. Rewording a description or renaming an argument is how an agent’s behaviour gets tuned. | Additive only. A breaking change mints /api/v2; v1 keeps its promise. |
| Shape | The same. MCP payloads are derived from the v1 response schemas, so the two describe provably identical objects. | The same, and it is the source the MCP derives from. |
| Auth | One personal access token, one scope set. | The same credential works on both. |
Wiring an agent? Stay here. Writing software other people install? The API-Referenz is the other half — it is the one that promises not to change under you.
1Mint a token
Every request carries a personal access token, minted in Motir under Settings → Account → Tokens. Choose the workspace it is bound to and grant it the narrowest scope set that does the job — the table at the bottom of this page says what each scope gates. A grant narrows your own role and never widens it, so a token can never do something you could not.
The secret is shown once, when the token is created. Copy it then; there is no way to read it again, and a lost token is replaced rather than recovered.
2Wire your client
Every client needs the same four facts under whatever names it gives them.
| URL | https://app.motir.co/api/mcp |
| Transport | Streamable HTTP — not SSE, and not a stdio command |
| Header | Authorization: Bearer <token>, on every request |
| Token | motir_pat_<your-token> — the one you minted in step 1 |
Keep the token out of a file your repository tracks. Where a client can read it from your environment or prompt you for it, the block below uses that instead of a literal — which is why two of them name MOTIR_TOKEN rather than a secret.
Claude Code
.mcp.json
{
"mcpServers": {
"motir": {
"type": "http",
"url": "https://app.motir.co/api/mcp",
"headers": { "Authorization": "Bearer motir_pat_<your-token>" }
}
}
}Or one command: claude mcp add --transport http motir https://app.motir.co/api/mcp --header "Authorization: Bearer motir_pat_<your-token>" · Claude Code documentation · format checked 2026-09-04
Cursor
~/.cursor/mcp.json — or .cursor/mcp.json for one project
{
"mcpServers": {
"motir": {
"url": "https://app.motir.co/api/mcp",
"headers": { "Authorization": "Bearer ${env:MOTIR_TOKEN}" }
}
}
}Cursor interpolates ${env:…}, so the token stays in your environment and out of the file. · Cursor documentation · format checked 2026-09-04
VS Code
.vscode/mcp.json
{
"inputs": [
{
"type": "promptString",
"id": "motir-token",
"description": "Motir personal access token",
"password": true
}
],
"servers": {
"motir": {
"type": "http",
"url": "https://app.motir.co/api/mcp",
"headers": { "Authorization": "Bearer ${input:motir-token}" }
}
}
}VS Code prompts for the token the first time the server starts and stores it securely — nothing secret is written to the file. · VS Code documentation · format checked 2026-09-04
Codex CLI
~/.codex/config.toml
[mcp_servers.motir] url = "https://app.motir.co/api/mcp" bearer_token_env_var = "MOTIR_TOKEN"
bearer_token_env_var takes the variable’s NAME, not the token. · Codex CLI documentation · format checked 2026-09-04
Any other streamable-HTTP client
whatever your client calls its config
Transport: streamable HTTP URL: https://app.motir.co/api/mcp Header: Authorization: Bearer motir_pat_<your-token>
Windsurf, Zed, Cline, Goose, or something you wrote yourself — the same four facts under different key names. · Any other streamable-HTTP client documentation · format checked 2026-09-04
3Check the connection
Restart the client and ask it what tools it has; the server answers with the whole catalogue, scoped to your grant. To check the endpoint itself before involving a client, ask it directly — this is the same handshake, with the token in your environment.
your machine
curl -sS -X POST https://app.motir.co/api/mcp \
-H "Authorization: Bearer $MOTIR_TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'An unauthorized answer is about the TOKEN, not the wiring. A missing, malformed, unknown, revoked or expired token all return the same refusal, deliberately — distinguishing them would turn the endpoint into an oracle that answers whether a secret exists. Check that the header is spelled Authorization, that the value begins Bearer, and that the token has not been revoked in Motir.
What a connection may call
Every tool is gated by a scope. The permissions you approved for a connected app, or the grant a token carries, decide which tools it may call — so the list your client shows is already scoped to you. These are read from Motir itself when this page is requested, so they are whatever the server ships right now.
| Scope | What it gates | Default |
|---|---|---|
project:browse | Open the project and read its work items, boards, backlog and reports. | Granted |
lesson:view | Read what the project's AI planner learned from its own planning work. | Granted |
lesson:manage | Retire a lesson or add one — both change the standing instructions the planner is given. | Granted |
lesson:reinforce | Note that a lesson's mistake happened again. It changes nothing the lesson says. | Granted |
work_item:edit | Create, update, assign and move work items, and transition them on the board. | Granted |
work_item:archive | Archive a work item and restore it later. Affects that item only — its children stay. | Granted |
work_item:delete | Permanently delete a work item and everything beneath it. Cannot be undone. | Off by default |
comment:add | Post comments on work items, and edit or delete your own. | Granted |
page:view | Open and read the project's pages. | Granted |
page:edit | Create pages, rename them and change what they say. | Granted |
sprint:manage | Start and complete Sprints, and rank the backlog. | Granted |
ai:plan | Submit a planning job that spends the workspace’s AI credits and proposes plan changes. | Granted |
ai:view_plan | Add proposals to a generated plan and close it for review. Reading a plan needs only project access. | Granted |
What next
MCP-Tools lists every tool the server exposes with the arguments it takes. The full reference in motir-core carries each tool’s complete description. Driving the same data from a terminal instead is the CLI.