Skip to content
Console
Menu

Generated Assets

Workflows

Getting Started

Authentication

KV Store

Connect an MCP client

The remote MCP server at api.sylphx.com/mcp, its sign-in, what it can read, and how to remove it.

The remote MCP server runs at https://api.sylphx.com/mcp. A client adds that address, sends you to sylphx.com to sign in, and then reads your Sylphx organization with the same API as the API reference. Nothing is installed and no key is copied. The local server (@sylphx/mcp) is the other way to connect, and the one that can change things today.

#Sign in

When a client first connects it opens a Sylphx page that names the app, shows where it will send you back to, and asks which organization it may see. Check the app: a verified app shows the host it was registered from, and an unverified one says so, so approve only a connection you just started. Choose the organization and approve. The access is read only.

#Add it to a client

Settings, Connectors, Add custom connector.
Name: Sylphx
URL:  https://api.sylphx.com/mcp

Menu names differ between versions of each client. Every one of them finds the sign-in on its own from the address.

#What it can do

The server lists the Sylphx methods that read: projects, databases, logs, traces and the rest of the API's list and get calls. A service that is not available yet has no tools, so nothing in the list answers "not implemented". access_whoami names the organization you chose.

A connected app never receives:

  • the right to change or delete anything (this version is read only);
  • anything that spends money, such as AI inference or a purchase;
  • sending mail or notifications;
  • secret values or the use of a stored key.

Use an API key or the local server for those.

#How long it lasts

The client holds an access token for one hour and renews it with a refresh token that lasts 30 days from its last use. If your role in the organization changes, or you leave it, the connection stops. Remove the connector in the client: one that supports revocation ends the grant at once. To end it from Sylphx's side, revoke the organization key labelled mcp: and the app's name (sylphx CLI or the API's access.api_keys.delete): that ends the whole connection, refresh token included. A Connected apps page in the console is coming.

#An API key instead

A script or CI job can skip the sign-in and send a key:

Shell
claude mcp add --transport http sylphx https://api.sylphx.com/mcp \
  --header "Authorization: Bearer $SYLPHX_API_KEY"

The key keeps its own scopes, and the server still lists read tools only.