- A Personal Access Token (recommended for your own use) — one command, no admin involvement, results respect your own permissions.
- An OAuth app — for shared, team, or admin-managed setups where an administrator issues credentials.
Personal Access Token (recommended)
Requires PipesHub 0.7.0 or later. Any user can do this; you do not need to be an admin.1
Mint a token
In PipesHub, go to Workspace → Developer settings → Personal Access Tokens → New token. Name it (for example The token is sent as a bearer header on every request, so the URL must be
claude-code), pick an expiry, keep the default scopes, and copy the two lines shown — they appear only once:https:// for anything other than a local instance — http://localhost:3000/mcp is fine on your own machine, http:// to a remote host is not.Export both in your shell. See Personal Access Tokens for scopes and revocation.2
Add the server
--scope user to make it available in every project instead of just the current one.3
Tell Claude when to use it
In the project you’re working in (not a PipesHub repository):and add the “Company knowledge” block from For coding agents to your
CLAUDE.md. Without this, a fresh chat has the tools but no reason to reach for them.4
Verify
pipeshub should show as connected. Then ask something only your company’s data can answer.Measured on a fresh
slim install of the released image with five documents indexed: steps 2–4 took 46 seconds end to end, returning a four-source cited answer.Project-scoped .mcp.json with a token
If you prefer a checked-in config, keep the token in the environment and reference it:
OAuth app (shared or admin-managed setups)
Claude Code also supports remote HTTP MCP servers with static OAuth credentials via--client-id, --client-secret, and --callback-port. PipesHub exposes discovery at /.well-known/oauth-protected-resource/mcp, so Claude Code auto-discovers the authorization and token endpoints. Use this when an administrator issues credentials for a team rather than each person minting their own token.
Before you start, create an OAuth app in PipesHub and note your Client ID and Client Secret. See MCP Server Overview.
Add with CLI
--client-secret without a value prompts for masked input. To skip the prompt, set the MCP_CLIENT_SECRET environment variable:Add with JSON
Project-scoped .mcp.json with OAuth
Create a .mcp.json file in your project root. This can be committed to version control (secrets stay out via env vars):
The client secret is stored in the system keychain, not in config files. You’ll be prompted to enter it when you first authenticate via
/mcp.Authenticate
After adding the server, run/mcp inside Claude Code and follow the browser login flow. Tokens are stored securely and refreshed automatically.