MCP Authentication
How AI tools sign in to the Monito MCP server, what they can do, and how to disconnect them.
Connecting an app
The hosted server uses OAuth. When an AI tool connects for the first time:
- Your browser opens Monito. Sign in if you are not signed in already.
- Monito shows which app is asking and where it will return you.
- Choose Allow. The app gets a token for your account and the browser returns to it.
Monito asks every time an app connects, even if you approved it before. Only allow apps you started connecting yourself.
What a connected app can do
A connected app acts as your Monito account through the MCP tools. It can:
- See your projects, test scenarios, runs and bug reports
- Create, change and delete projects, scenarios, automations and fixtures
- Run tests, which spends your credits
Its token cannot create API keys, change your plan or manage connected apps; those need you signed in to the dashboard. The MCP tools also never handle saved login secrets: set those in the dashboard or with monito credential set. Runs an app starts are marked with its name.
Disconnecting
Open Settings → Connected apps in the dashboard and choose Disconnect. The app loses access immediately; runs it already started keep going. Access tokens also expire after an hour, and apps renew them for up to 30 days without asking you again.
Headless clients
Clients that cannot open a browser can send an API key instead of using OAuth:
x-api-key: monito_...For example, in Claude Code:
claude mcp add --transport http monito https://www.monito.dev/api/mcp \
--header "x-api-key: $MONITO_API_KEY"Local server
The local server (npx -y @monitodev/cli mcp) uses the same credentials as the CLI: your monito auth login session, or MONITO_TOKEN. See CLI authentication.