# Connect Claude Code

BakedBrie's MCP server is a remote HTTP server. Claude Code connects to it with a bearer token in the `Authorization` header.

| Item | Value |
|---|---|
| Server name | `bakedbrie` |
| URL | `https://api.bakedbrie.com/mcp` |
| Transport | `http` |
| Header | `Authorization: Bearer ${BAKEDBRIE_TOKEN}` |

## Before you start

You need a BakedBrie API token (`bbk_prd_...`). If you do not have one, see [Tokens and the runner](/docs/tokens-and-runner). A Full control token can do everything the user can do on the boards they can open. A Read only token can only read.

## Step 1: put the token in an environment variable

The user sets it in their own shell. Never write the token into a file you commit, and never paste it into chat.

```bash
export BAKEDBRIE_TOKEN='bbk_prd_...'
```

To keep it across sessions, the user can add that line to their shell profile (for example `~/.zshrc`) or load it from their keychain. Start Claude Code from a shell where `BAKEDBRIE_TOKEN` is set.

## Step 2 (recommended): add a .mcp.json file

Create `.mcp.json` in the project root. Claude Code expands `${BAKEDBRIE_TOKEN}` from the environment when it starts, so the file never holds the token itself and is safe to commit.

```json
{
  "mcpServers": {
    "bakedbrie": {
      "type": "http",
      "url": "https://api.bakedbrie.com/mcp",
      "headers": {
        "Authorization": "Bearer ${BAKEDBRIE_TOKEN}"
      }
    }
  }
}
```

This is the same snippet the web app shows under Settings, Apps and API, Connect Claude Code.

In an interactive session, Claude Code asks the user to approve a project server from `.mcp.json` the first time. Until then `/mcp` shows it as pending approval. `claude -p` runs skip that prompt.

## Step 2 (alternative): claude mcp add

`claude mcp add` stores the header value literally in `~/.claude.json`. Environment variable expansion works only in `.mcp.json`, so with this command the token itself is saved in plain text in that file. Prefer `.mcp.json`. If the user still wants the server in every project:

```bash
claude mcp add --transport http bakedbrie https://api.bakedbrie.com/mcp \
  --header "Authorization: Bearer $BAKEDBRIE_TOKEN" --scope user
```

Order matters: `--transport` first, then the name, then the URL, then `--header`. `--scope` takes `local` (default, this project only), `project` (writes `.mcp.json`) or `user` (all projects).

## Step 3: check the connection

```bash
claude mcp list
claude mcp get bakedbrie
```

Inside Claude Code, run `/mcp`. The `bakedbrie` server should show as connected.

Then call the `whoami` tool. It returns the workspace, your role, the token preset and which capabilities are on. See [whoami](/docs/reference/tools/whoami).

## If it does not connect

| What you see | Likely cause | What to do |
|---|---|---|
| `/mcp` says the server needs authentication, or calls fail with `UNAUTHENTICATED` | `BAKEDBRIE_TOKEN` was empty or wrong when Claude Code started, or the token was revoked or expired | Set the variable in the same shell, restart Claude Code. If the token was revoked or is older than 90 days, mint a new one. |
| `MCP_DISABLED` | MCP is turned off on this BakedBrie server | Nothing to fix on your side. Tell the user. |
| `API_TOKENS_DISABLED` | API tokens are turned off on this server | Tell the user. |
| `INTERACTIVE_SESSION_REQUIRED` | The request did not carry an API token | Check the header is exactly `Authorization: Bearer bbk_...`. |
| `TOKEN_RUNNER_ONLY` | You used a runner key | Runner keys work only with `bakedbrie-runner`. Mint a Full control or Read only token. |
| `TOKEN_WORKSPACE_MISMATCH` | A request named a workspace the token does not belong to | Do not send `X-Workspace-Id`, or send the token's own workspace. |

More codes: [Refusals](/docs/refusals).

## Remove it

```bash
claude mcp remove bakedbrie
```

Or delete the `bakedbrie` entry from `.mcp.json`. To stop the token working everywhere, revoke it in Settings, Apps and API.

## Next step

Read [Concepts](/docs/concepts), then call `whoami`.

<!--
Sources checked 2026-09-23:
https://code.claude.com/docs/en/mcp (claude mcp add --transport http with --header, scopes, .mcp.json format, ${VAR} expansion only in .mcp.json, project server approval, /mcp status)
Server side: apps/api/src/mcp/server.ts (POST /mcp, Bearer bbk_ token), apps/web/components/v21/apps-api/connect-claude-code.tsx (snippet), infra/topology.json (api origin)
-->
