# Connect Cursor, VS Code and Codex

> Add the MISSIN MCP server to Cursor, VS Code, Codex or any client that speaks Streamable HTTP or stdio, with a secret key kept out of your repository.

The hosted MCP server at `https://api.missin.co.uk/mcp` works with any client that can send a header on Streamable HTTP, and `npx -y @missin/cli mcp` serves the same tools over stdio for any client that starts a command. Both take a secret key, and both give the assistant the key's access level and no more. [Connect Claude](https://developer.missin.co.uk/mcp/connect-claude.md) has the Claude routes and the access levels.

Create the key in Settings > Developers > Create key (https://app.missin.co.uk/settings/developers). It is shown once. Pick Read to let the assistant look only, or Write to let it change partners, campaigns and posts and start captures.

> **Warning:**
> Keep the key out of files you commit. Both editors below can read it from somewhere else, so the config file holds a reference and never the key.

## Add the server

**Cursor**

Cursor reads `~/.cursor/mcp.json` for every project, or `.cursor/mcp.json` in one project. Put the key in your shell environment, start Cursor from that shell, and refer to it:

```json
{
  "mcpServers": {
    "missin": {
      "url": "https://api.missin.co.uk/mcp",
      "headers": {
        "Authorization": "Bearer ${env:MISSIN_API_KEY}"
      }
    }
  }
}
```

Cursor resolves `${env:NAME}` in `url` and `headers`. To load more tools, add toolsets to the URL, for example `https://api.missin.co.uk/mcp?toolsets=forms,waitlists`.

To run the server on your own machine instead, give Cursor a command:

```json
{
  "mcpServers": {
    "missin": {
      "command": "npx",
      "args": ["-y", "@missin/cli", "mcp"],
      "env": { "MISSIN_API_KEY": "${env:MISSIN_API_KEY}" }
    }
  }
}
```

**VS Code**

VS Code reads `.vscode/mcp.json` in a project, or your user configuration (run **MCP: Open User Configuration** from the Command Palette). The top-level object is `servers`, and an `inputs` entry asks for the key the first time the server starts and remembers it, so it never sits in the file:

```json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "missin-key",
      "description": "MISSIN secret API key (sk_live_...)",
      "password": true
    }
  ],
  "servers": {
    "missin": {
      "type": "http",
      "url": "https://api.missin.co.uk/mcp",
      "headers": {
        "Authorization": "Bearer ${input:missin-key}"
      }
    }
  }
}
```

To run the server on your own machine instead, use a stdio server in the same file:

```json
{
  "servers": {
    "missin": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@missin/cli", "mcp"],
      "env": { "MISSIN_API_KEY": "${input:missin-key}" }
    }
  }
}
```

Use the same `inputs` entry as above for the key. Start the server from the editor's MCP list, then ask the assistant which workspace it is connected to.

**Codex**

Codex reads the key from an environment variable named by `--bearer-token-env-var`, so the key never sits in its config. Export `MISSIN_API_KEY` in your shell, then:

```bash
codex mcp add missin --url https://api.missin.co.uk/mcp --bearer-token-env-var MISSIN_API_KEY
```

That writes the server to `~/.codex/config.toml`, which the Codex CLI, the Codex IDE extension and the ChatGPT desktop app share. `codex mcp list` shows it, and `/mcp` lists it inside a session.

**Any other client**

A client that speaks Streamable HTTP and can send a header works: `POST https://api.missin.co.uk/mcp` with `Authorization: Bearer sk_live_...`. Only a secret key is accepted, and `x-api-key` alone is refused. The server is stateless and answers JSON, so there is no session to keep.

A client that starts a command uses stdio: run `npx -y @missin/cli mcp` with `MISSIN_API_KEY` in its environment, and `--toolsets` or `MISSIN_TOOLSETS` to choose tools. See [the CLI page](https://developer.missin.co.uk/tools/cli.md).

## Let an agent install it

The copyable install prompt on [Connect Claude](https://developer.missin.co.uk/mcp/connect-claude.md#let-an-agent-install-it) covers Claude Code, Codex and Cursor: the agent checks the endpoint, asks for the key without echoing it, adds the server and calls `whoami`.

## Check it works

Ask the assistant "which workspace are you connected to, and what can you change?". It calls `whoami`, which answers with the workspace, the key's name and its access level. If the server shows as failed, see the troubleshooting list in [Connect Claude](https://developer.missin.co.uk/mcp/connect-claude.md#troubleshooting): a `401` is a missing or revoked key, and a `403` with `secret_key_required` is a publishable key.

## Sources

The vendors' own docs for [Cursor's MCP configuration](https://cursor.com/docs/mcp), [VS Code's MCP configuration reference](https://code.visualstudio.com/docs/agents/reference/mcp-configuration) and [Codex's MCP configuration](https://learn.chatgpt.com/docs/extend/mcp?surface=cli). ChatGPT's own custom MCP servers offer OAuth or no authentication only ([Add custom MCP server](https://developers.openai.com/api/docs/guides/custom-mcp-server)), so they cannot send a MISSIN key.

Source: https://developer.missin.co.uk/mcp/other-clients
