CodeCargo logo

AI & Agents

MCP Credentials

An MCP credential lets Claude Code, Cursor, VS Code, or another AI client call CodeCargo as you. It can only do what you can do, and only in the organizations you allow.

Create a credential

Open Profile → MCP credentials and click New credential.

  1. Name the credential and set an expiry. The longest lifetime is 365 days.
  2. Choose the organizations it can act in. You can select an organization only when its plan includes MCP client access; others are listed but disabled. Choose All my organizations to include every organization you belong to, including ones you join later. That option is available when at least one of your organizations includes MCP client access.
  3. Set access for each product area. The grid starts at read everywhere. Read everywhere, Write everywhere, and Clear apply to the whole grid. Granting write asks you to confirm. If CargoWall is set to write, the confirmation names its enforcement mode.
  4. Click Submit, then copy the secret from the dialog that opens.
The New MCP credential slideout: Name Cursor — payments team, Expires 90 days, Organizations with Acme Corp and Acme Labs ticked and Acme Open Source disabled because its plan doesn't include MCP client access, and Access by area, with Read everywhere, Write everywhere and Clear above a grid where Migration Assistant is set to Read and write and the other areas to Read

The secret is shown once

Copy the credential before you close the dialog. It cannot be shown again. Rotate the credential if you lose it.

The dialog includes connection snippets for Claude Code, Cursor, VS Code, and a generic Streamable HTTP client. The VS Code snippet asks for the secret in an input variable instead of writing it into .vscode/mcp.json, which is usually committed. Claude Desktop and claude.ai are not listed: their connectors expect OAuth, not a bearer credential.

The MCP credential created dialog: a note to copy the secret now, the secret with a copy button, and Claude Code, Cursor, VS Code and Other tabs, with the Claude Code command that adds CodeCargo's MCP endpoint using the secret as a bearer token

One credential covers every organization it can act in, so one client configuration is enough. After connecting, ask the client to run codecargo_get_started.


What the credential can do

Every call runs as you. Your role in that organization applies, and the access you granted can only narrow it. The organization's plan limits the call the same way it limits you in CodeCargo. A call into an organization whose plan does not include MCP client access is refused.

Leaving an organization ends the credential there on the next call. Nothing is revoked, and it keeps working in your other organizations. With All my organizations, a newly joined organization is included on the next call.

If your GitHub sign-in has expired, the credential stops working until you sign in to CodeCargo again.


Choosing an organization

A call acts in one organization. Platform tools take org_id. CargoWall tools take org. You can pass an id, an alias, or a name.

When the credential can act in exactly one organization, you can omit it. When it can act in several, omitting it — or passing a name or alias that matches more than one — refuses the call and lists those organizations. The client does not pick one for you.

codecargo_list_orgs lists them: id, alias, your role, and whether the plan includes MCP client access.


Rotate and revoke

Each row on Profile → MCP credentials shows the credential's organizations, access, status, last use, and expiry. Its options menu (⋯) has Rotate and Revoke.

The Credentials card on Profile → MCP credentials, with a New credential button and four credentials: Claude Code in Acme Corp, Cursor — migration in Acme Corp and Acme Labs, VS Code — read only in all your organizations and never used, and an expired Audit log export, each with its access, status, last use, expiry, and an options menu
  • Rotate issues a new secret with the same name, access, organizations, and lifetime, and revokes the old credential. It does not add organizations or raise access. Create a new credential to change either. You can rotate an expired credential. A revoked credential cannot be rotated. Rotation is refused when no organization it can act in still includes MCP client access.
  • Revoke stops the credential everywhere. Revoking it again does nothing.

A credential issued for specific organizations stays limited to those organizations, and it is listed on the owner's profile. Create a new one to reach more.


Credentials that reach your organization

If you administer the organization, open organization settings and go to MCP. Servers is the catalog of MCP servers your agents call. Clients lists credentials that can call CodeCargo here: ones that name this organization, and All my organizations credentials whose owner is a member.

Each row shows the owner and the credential's reach — all of the owner's organizations, or how many it names — but not the other organizations' names. Revoke stops that credential everywhere, not only here. Create and rotate credentials from the owner's profile, not from this list.

The Clients tab of the organization's MCP settings: a note that credentials are personal, linking to Profile → MCP credentials, and five credentials that reach the organization, each with its owner, its reach (this organization only, this and other organizations, or all of the owner's organizations), access, status, last use, expiry, and an options menu

If the plan no longer includes MCP client access, credentials that still reach the organization can still be listed and revoked.


Pairs Well With