# Connecting Claude Code and Cursor

Command-line and IDE clients — Claude Code, Cursor, the Claude API, and anything
else that speaks MCP over HTTP — authenticate with an API token rather than a
sign-in flow. You create the token in ResponseHub, then pass it to the client as
an `Authorization` header.

## Create an API token

1. Open **API** from your account menu.

2. Select **Create an API Token**.

3. Give it a **Name** you will recognise later, such as the client it is for.

   The **Account** is fixed to the account you are working in — a token can only
   ever reach that account's data.

4. Choose the **Access** level: **Read only** or **Read & write**.

5. Choose when it **Expires**: **Never**, **In 90 days**, or **In 1 year**.

6. Save the token, then copy the secret straight away — it is shown once,
   highlighted at the top of the token's page.

**The secret is shown once:** ResponseHub stores only a hash of the token, so the secret cannot be shown
again. If you lose it, use **Roll Secret** on the token to issue a new one —
which immediately stops any client still using the old secret.

Give a client **Read only** unless it genuinely needs to change things. A
read-only token cannot create, update or delete anything, whatever the assistant
is asked to do.

## Claude Code

Run this in your terminal, replacing `YOUR_TOKEN` with the secret you copied:

```bash
claude mcp add --transport http responsehub https://app.responsehub.io/mcp \
  --header "Authorization: Bearer YOUR_TOKEN"
```

The same command, ready to copy, is on the **MCP** tab of the **API** screen in
ResponseHub.

## Cursor and other clients

Clients that take a JSON configuration file want the URL and the header:

```json
{
  "mcpServers": {
    "responsehub": {
      "url": "https://app.responsehub.io/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_TOKEN"
      }
    }
  }
}
```

The server speaks streamable HTTP and is stateless: every call is a `POST` to
`/mcp` carrying its own credentials, so there is no session to establish and
nothing to keep open.

**Keep the token out of version control:** Anything holding the header is holding a live credential. Most clients let you
read it from an environment variable — prefer that to committing a config file
with the secret in it.

## Rolling and revoking

Open the token from the **API** screen to:

- **Roll Secret** — replace the secret while keeping the token's name, account
  and access. Clients using the old secret stop working immediately.
- **Revoke Token** — delete it outright.

A token also stops working on its own when it expires, or when the user it
belongs to leaves the account it is bound to.

## Next steps

- [What connected assistants can do](/help/mcp/tools/)
- [Uploading documents](/help/mcp/uploading-documents/)
- [Permissions and safety](/help/mcp/permissions-and-safety/)