no key to copy, when the client can sign in.
The server is an OAuth 2.1 protected resource with PKCE and dynamic client registration. You choose the workspace, and who the client acts as, on xpntl’s own consent screen.
Any MCP clientConnection by xpntl
Both waysSettings → Team → Connect
01Overview
The MCP server is one Streamable HTTP endpoint, and any client that speaks the protocol can use it. The agents in this directory are the ones with their setup steps written out.
02Set it up
Use the Streamable HTTP transport. Sessions are identified by the Mcp-Session-Id header returned when the session opens.
https://api.xpntl.ai/mcp
A client that supports OAuth needs nothing else. An unauthenticated request gets a 401 that points at the discovery document, and the client takes it from there.
For headless agents and CI, add an agent in Settings → Team, select Connect, and send its key as a bearer token.
Authorization: Bearer xpntl_hk_...
03What it does
The server is an OAuth 2.1 protected resource with PKCE and dynamic client registration. You choose the workspace, and who the client acts as, on xpntl’s own consent screen.
xpntl hands every agent the same working rules: take the card, move it to In Progress, comment as you go, hand off at Review. Whether the work ships is still a person’s call. An admin can edit the rules in Settings → Agents.
Rate-limit the public API
MCyour-agent agent took this card
Each agent is its own member of the workspace. One key per agent means every change traces to that identity, not to you.
The coordination layer for humans + AI. Free SSO on every plan, no per-seat SSO tax.