# Connect Elaichi to Claude Code

> To connect Elaichi to Claude Code, run one claude mcp add command and sign in with OAuth. The entry holds no secret, so a project .mcp.json is safe to commit.

**TL;DR** To connect Elaichi to Claude Code, add https://api.elaichi.ai/mcp as a remote HTTP server with claude mcp add, then sign in from /mcp in the browser. The entry is a URL with no key or header, so a checked-in .mcp.json gives every engineer the same address while each one signs in as themselves. After that, the engineer's Elaichi role, what is shared with them and any restrictions decide which Jira, Slack and other tools Claude Code can call.

Claude Code is Anthropic's coding agent for the terminal. Give it a bug, and it reads the Jira issue, searches Slack and edits code over dozens of steps. Each step that reaches a company app needs a credential. The usual answer is a personal token pasted into a config file, one per app, per engineer. One endpoint behind OAuth replaces those tokens.

## How do you connect Elaichi to Claude Code?

Run one `claude mcp add` command with Elaichi's endpoint, `https://api.elaichi.ai/mcp`, then sign in from Claude Code in your browser. That is the whole job to connect Elaichi to Claude Code. There is no API key, no header and no server to run.

MCP (Model Context Protocol) is the standard way an AI assistant calls tools in other apps. Its [specification](https://modelcontextprotocol.io/specification/2026-07-28) is open for anyone to read. Elaichi exposes all connected SaaS accounts at one organization-wide address, `POST /mcp`, protected by OAuth.

## Which command adds Elaichi to Claude Code?

`claude mcp add` with the HTTP transport, a name and the URL. Anthropic's docs give the form `claude mcp add --transport http <name> <url>` ([Claude Code MCP docs](https://code.claude.com/docs/en/mcp), checked October 2026). For Elaichi, at user scope:

```bash
claude mcp add --transport http elaichi --scope user https://api.elaichi.ai/mcp
```

Leave out `--header`. Elaichi does not take a bearer token you paste. Copy the URL exactly, with no trailing slash and on the `api` host. With a trailing slash the endpoint returns 404, and on `app.elaichi.ai` it returns 405. Neither starts sign-in.

## Should Elaichi live at user, project or local scope?

User scope for one engineer, project scope for a team. Claude Code stores a local or user server in `~/.claude.json`, and a project server in `.mcp.json` at the repository root. Local is the default and loads in one project only. User scope loads in all your projects. Project scope is shared through version control.

A project entry for Elaichi looks like this:

```json
{
  "mcpServers": {
    "elaichi": {
      "type": "http",
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}
```

That file is safe to commit, because it holds no secret. Every clone carries the same address, and each engineer still signs in as themselves. In interactive sessions, Claude Code asks each engineer to approve a project server from `.mcp.json` before it connects. In `claude -p` runs, Agent SDK sessions and cloud sessions it cannot show that prompt, and the docs say it "loads project-scoped servers without asking". The entry holds no secret, so loading it exposes no credential.

A platform lead can pin the requested scopes in the same file with Claude Code's `oauth.scopes` field. Add `"oauth": { "scopes": "mcp:read mcp:write mcp:tools" }` to the entry, and Claude Code asks for those scopes instead of the ones Elaichi's metadata lists. Treat that pin as a default, not a ceiling. Claude Code's precedence runs local, then project, then user, and it uses the whole entry from the highest source with no merging. An engineer who adds a local `elaichi` entry replaces the project one. To hold deletes back reliably, restrict the delete tools in Elaichi. That binds whichever entry an engineer uses.

## What happens when an engineer signs in?

Claude Code opens Elaichi's sign-in in the browser, and the engineer approves a consent screen. Start it with `/mcp` inside a session, or with `claude mcp login elaichi` from the shell. Over SSH, `claude mcp login` prints the URL instead, and `--no-browser` forces that.

Sign-in needs a browser. Claude Code running headless in CI, or in a terminal with no access to a browser, cannot complete Elaichi's OAuth sign-in. Connect from a machine where the engineer can open the browser, and do not plan on unattended CI runs.

Claude Code registers itself through dynamic client registration ([RFC 7591](https://www.rfc-editor.org/rfc/rfc7591)), which Elaichi supports, so there is no client ID to enter. It picks a random local port for the callback each time. Elaichi checks the callback address exactly, except that a loopback address may change its port. That is the rule [RFC 8252](https://www.rfc-editor.org/rfc/rfc8252) sets for native apps.

On Elaichi's consent screen, the engineer picks one organization. Then come up to four checkboxes: read data, create and change data, run connected tools, and delete data. Everything requested starts ticked except delete, which never does. Keep **Run your connected tools** ticked, or the agent reaches no connected app. The request lasts 30 minutes and works once.

## How do you confirm Claude Code can see the tools?

Check the server first, then ask for one read. `claude mcp list` shows a health status beside each server, such as Connected or Needs authentication. `claude mcp get elaichi` shows one server's details, and `/mcp` shows the same inside a session.

Expect a short tool list. In Elaichi, connected tools are never listed one by one, however few there are. Claude Code calls `search_tools` to find a connected tool, then `execute_tool` to run it. Those two, plus any Elaichi operations the engineer's role and grant allow, are the whole list.

Then ask a real question, such as "List my open Jira issues". If the list is empty or an app is missing, [the missing-tools checklist](/blog/mcp-tools-not-showing/) walks the causes in order.

## How do Jira, Slack and GitHub reach Claude Code?

Jira and Slack go through Elaichi, and GitHub does not. An admin or engineer connects each SaaS account once, from a catalog of 500+ connectors that Elaichi authors and serves. A shared Jira connection reaches Jira as the account that connected it. Elaichi's role, restrictions and audit trail are per engineer. Where Jira's own permissions and log must be the engineer's, each engineer connects their own account once. A separate credential service holds each account's secrets, encrypted at rest, so no Jira or Slack token sits in a dotfile.

GitHub is not in Elaichi's [connector catalog](/connectors/). GitHub runs its own remote server at `https://api.githubcopilot.com/mcp`. [GitHub's guide for Claude Code](https://github.com/github/github-mcp-server/blob/main/docs/installation-guides/install-claude.md) (checked October 2026) adds that server with a personal access token in a header. That one token stays on the laptop, and calls to it do not pass through Elaichi's restrictions or audit trail. The other route is an Elaichi custom connector, which needs the high-trust `connector:create` permission.

The [Jira connector](/connectors/jira/) and the [Slack connector](/connectors/slack/) list every tool a rule can name.

## Can one URL serve Claude, ChatGPT, Cursor and Claude Code?

Yes. Elaichi's endpoint is one address for every member, and clients point at it and sign in: Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent. An admin adds it once where a client allows, and each person connects it there and signs in with their own grant.

Claude Code has a shortcut for people who already use Claude. Anthropic's docs say connectors added in claude.ai are available automatically in Claude Code when you log in with a claude.ai account ([using claude.ai connectors in Claude Code](https://code.claude.com/docs/en/mcp#use-mcp-servers-from-claude-ai)). So Elaichi, added as a custom connector in Claude, can appear in `/mcp` with no command at all. That works only with a claude.ai subscription login, not with an API key or a cloud provider. A server you add yourself with the same URL takes precedence, and `/mcp` then lists the connector as hidden.

[The Claude setup](/blog/connect-elaichi-to-claude/) and [the Cursor setup](/blog/cursor-mcp-one-endpoint-vs-per-developer/) use the same address unchanged.

## What do restrictions and the audit log add for Claude Code?

Elaichi checks every call against the engineer's role, shares and restrictions, whatever approval mode Claude Code runs in. Restrictions decide which connectors and which individual tools a target may reach, and the audit trail names the engineer and the account each call reached. Claude Code's settings-file permission rules cannot tell a Jira read from a Jira delete, because every connected tool runs through one tool name, `execute_tool`. Only a deny rule passed on the command line can name one tool. [MCP for coding agents across an engineering org](/blog/coding-agents-company-tools/) makes the full argument, including frozen arguments and how to tell which agent made a call. A restriction change takes about two minutes to apply.

## How do you disconnect Claude Code from Elaichi?

Remove it in Claude Code, then end the grant in Elaichi. `claude mcp logout elaichi` clears the credentials Claude Code stores. To be sure the grant has ended in Elaichi, disconnect it in **Settings**, under **Connected apps**. When an admin removes or suspends a member, removing or suspending a member revokes every live grant in the same transaction as the membership change, so that engineer's next call fails.

## What goes wrong most often, and how do you fix it?

Most failures are the URL, an expired request or a missing checkbox. Each has a quick fix:

- **Sign-in never opens.** Check the URL for a trailing slash or the `app` host. In CI or a terminal with no browser access, sign-in cannot finish at all, so connect from a machine with a browser.
- **The consent screen says the request is no longer valid.** It expired or was used. Run `/mcp` again.
- **A tool error names a checkbox.** Elaichi answers with an error telling the engineer to reconnect and allow it. Run `claude mcp logout elaichi`, then `claude mcp login elaichi`, and tick the box. If you pinned scopes, add the missing one to `oauth.scopes` first.
- **The list is empty for everyone in a role.** The role may lack `tool:execute`, which an admin fixes.
- **A 429 mid-task.** Elaichi allows 120 MCP requests a minute per token. Wait a minute.

[What each OAuth error means](/blog/mcp-oauth-errors/) covers the rest, with who fixes each one.

## When is Elaichi more than a Claude Code user needs?

When one engineer uses Claude Code against one app they own. That app's own MCP server, signed in with OAuth, is enough. Revisit when a second app arrives, a contractor joins, or someone asks which agent changed a ticket. [When you don't need an MCP gateway yet](/blog/when-you-dont-need-an-mcp-gateway/) lists the signals.

Gold lists at $15 per user per month in USD, and the [pricing page](/pricing/) shows your region's price. Gold starts with a 14-day trial, no credit card to start. Checkout does collect a card, and it sets the paid trial to the remaining days rather than granting a fresh 14, so it is one continuous trial rather than two. For the wider picture, read [what an MCP control plane is](/blog/what-is-an-mcp-control-plane/), or pick a first app from the [connector catalog](/connectors/).

## FAQ

### Can one MCP server URL work in Claude, ChatGPT, Cursor and Claude Code?

Yes, with Elaichi. Its endpoint, https://api.elaichi.ai/mcp, is the same for every client and every member of the organization. Each client adds it once, and each person signs in with their own OAuth grant, so the address never changes and only the grant behind it differs.

### How do I connect Claude Code to Jira and Slack for a whole engineering team?

Connect Jira and Slack once in Elaichi, then point every engineer's Claude Code at Elaichi's endpoint. Each engineer signs in as themselves, so their Elaichi role, what is shared with them and any restrictions decide what their agent can call. A shared Jira connection reaches Jira as the account that connected it. Where Jira's own permissions and log must be the engineer's, each engineer connects their own account once. GitHub is not in Elaichi's connector catalog, so GitHub's own MCP server sits beside Elaichi or a custom connector fills the gap.

### How do you give AI agents access to SaaS apps without a shared service account?

Give each person their own OAuth grant to one endpoint instead of one account that everybody's agent uses. With Elaichi, the grant of the person who signed in authorizes every call, the audit trail names that person, and removing them ends that grant without touching anyone else's access. Where the app itself must see the engineer, each engineer connects their own account.

### Is it safe to commit an Elaichi entry to .mcp.json?

Yes. The entry holds a public URL and nothing else: no token, no header and no client secret. In interactive sessions, Claude Code asks each engineer to approve a project server before it connects. In claude -p runs, Agent SDK sessions and cloud sessions, it loads project-scoped servers without asking. Either way the entry exposes no credential, and each engineer signs in as themselves.

### Why does Claude Code show only a few Elaichi tools?

In Elaichi, connected tools are never listed one by one, however few there are. Claude Code calls search_tools to find a connected tool, then execute_tool to run it. The /mcp list therefore stays short by design, and a short list is not a broken connection.

## Read next

- [Connect Elaichi to Claude](/blog/connect-elaichi-to-claude/) — To connect Elaichi to Claude, add one URL as a custom connector and sign in with OAuth. On Team and Enterprise, an Owner adds it once for everyone.
- [Connect Elaichi to Cursor for a whole team](/blog/cursor-mcp-one-endpoint-vs-per-developer/) — To connect Elaichi to Cursor, add one URL to mcp.json or share it as a Team MCP server, and each developer signs in with OAuth. No API key.
- [Fix OAuth errors when adding an MCP connector](/blog/mcp-oauth-errors/) — Most OAuth errors when adding an MCP connector come from the URL, the account or a missing checkbox. What each Elaichi error means, and who fixes it.
