Connecting Claude Code and Cursor
Command-line and IDE clients — Claude Code, Cursor, the Claude API, and anything
else that speaks MCP over HTTP — authenticate with an API token rather than a
sign-in flow. You create the token in ResponseHub, then pass it to the client as
an Authorization header.
Create an API token
Section titled “Create an API token”-
Open API from your account menu.
-
Select Create an API Token.
-
Give it a Name you will recognise later, such as the client it is for.
The Account is fixed to the account you are working in — a token can only ever reach that account’s data.
-
Choose the Access level: Read only or Read & write.
-
Choose when it Expires: Never, In 90 days, or In 1 year.
-
Save the token, then copy the secret straight away — it is shown once, highlighted at the top of the token’s page.
Give a client Read only unless it genuinely needs to change things. A read-only token cannot create, update or delete anything, whatever the assistant is asked to do.
Claude Code
Section titled “Claude Code”Run this in your terminal, replacing YOUR_TOKEN with the secret you copied:
claude mcp add --transport http responsehub https://app.responsehub.io/mcp \ --header "Authorization: Bearer YOUR_TOKEN"The same command, ready to copy, is on the MCP tab of the API screen in ResponseHub.
Cursor and other clients
Section titled “Cursor and other clients”Clients that take a JSON configuration file want the URL and the header:
{ "mcpServers": { "responsehub": { "url": "https://app.responsehub.io/mcp", "headers": { "Authorization": "Bearer YOUR_TOKEN" } } }}The server speaks streamable HTTP and is stateless: every call is a POST to
/mcp carrying its own credentials, so there is no session to establish and
nothing to keep open.
Rolling and revoking
Section titled “Rolling and revoking”Open the token from the API screen to:
- Roll Secret — replace the secret while keeping the token’s name, account and access. Clients using the old secret stop working immediately.
- Revoke Token — delete it outright.
A token also stops working on its own when it expires, or when the user it belongs to leaves the account it is bound to.