AI & Agents
MCP Credentials
An MCP credential lets Claude Code, Cursor, VS Code, or another AI client call CodeCargo as you. It can only do what you can do, and only in the organizations you allow.
Create a credential
Open Profile → MCP credentials and click New credential.
- Name the credential and set an expiry. The longest lifetime is 365 days.
- Choose the organizations it can act in. You can select an organization only when its plan includes MCP client access; others are listed but disabled. Choose All my organizations to include every organization you belong to, including ones you join later. That option is available when at least one of your organizations includes MCP client access.
- Set access for each product area. The grid starts at read everywhere. Read everywhere, Write everywhere, and Clear apply to the whole grid. Granting write asks you to confirm. If CargoWall is set to write, the confirmation names its enforcement mode.
- Click Submit, then copy the secret from the dialog that opens.
The secret is shown once
Copy the credential before you close the dialog. It cannot be shown again. Rotate the credential if you lose it.
The dialog includes connection snippets for Claude Code, Cursor, VS Code, and a generic Streamable HTTP client. The VS Code snippet asks for the secret in an input variable instead of writing it into .vscode/mcp.json, which is usually committed. Claude Desktop and claude.ai are not listed: their connectors expect OAuth, not a bearer credential.
One credential covers every organization it can act in, so one client configuration is enough. After connecting, ask the client to run codecargo_get_started.
What the credential can do
Every call runs as you. Your role in that organization applies, and the access you granted can only narrow it. The organization's plan limits the call the same way it limits you in CodeCargo. A call into an organization whose plan does not include MCP client access is refused.
Leaving an organization ends the credential there on the next call. Nothing is revoked, and it keeps working in your other organizations. With All my organizations, a newly joined organization is included on the next call.
If your GitHub sign-in has expired, the credential stops working until you sign in to CodeCargo again.
Choosing an organization
A call acts in one organization. Platform tools take org_id. CargoWall tools take org. You can pass an id, an alias, or a name.
When the credential can act in exactly one organization, you can omit it. When it can act in several, omitting it — or passing a name or alias that matches more than one — refuses the call and lists those organizations. The client does not pick one for you.
codecargo_list_orgs lists them: id, alias, your role, and whether the plan includes MCP client access.
Rotate and revoke
Each row on Profile → MCP credentials shows the credential's organizations, access, status, last use, and expiry. Its options menu (⋯) has Rotate and Revoke.
- Rotate issues a new secret with the same name, access, organizations, and lifetime, and revokes the old credential. It does not add organizations or raise access. Create a new credential to change either. You can rotate an expired credential. A revoked credential cannot be rotated. Rotation is refused when no organization it can act in still includes MCP client access.
- Revoke stops the credential everywhere. Revoking it again does nothing.
A credential issued for specific organizations stays limited to those organizations, and it is listed on the owner's profile. Create a new one to reach more.
Credentials that reach your organization
If you administer the organization, open organization settings and go to MCP. Servers is the catalog of MCP servers your agents call. Clients lists credentials that can call CodeCargo here: ones that name this organization, and All my organizations credentials whose owner is a member.
Each row shows the owner and the credential's reach — all of the owner's organizations, or how many it names — but not the other organizations' names. Revoke stops that credential everywhere, not only here. Create and rotate credentials from the owner's profile, not from this list.
If the plan no longer includes MCP client access, credentials that still reach the organization can still be listed and revoked.
