Authentication
Choose how your AI assistant authenticates with Meldoc. For Claude.ai and Claude Desktop, connect with a custom connector — OAuth (browser login) is recommended, with a scoped token available for restricted access. IDEs and CLI tools use an integration token. Device flow is available for headless environments.
Claude.ai & Claude Desktop (custom connector)
Connect Claude.ai (the web chat) and Claude Desktop with a custom connector pointed at https://api.meldoc.io/mcp.
Recommended: OAuth (browser login)
Each person signs in with their own Meldoc account, so the connector carries their own permissions — nothing to create or share.
- In Claude, open Settings → Connectors → Add custom connector.
- Enter the Server URL
https://api.meldoc.io/mcpand add the connector. - Approve access on the Authorize Access page that opens.
No token needed; access is renewed silently afterward.
Optional: scoped access with a token (Client ID + Secret)
Use this when someone should not have a full Meldoc account but needs access to specific documents — for example, giving a wider team read-only access to a few projects. Create a scoped integration token and share it as a connector; everyone using it gets exactly the token’s access:
- Server URL —
https://api.meldoc.io/mcp - Client ID — the token’s auto-generated Client ID (e.g.
acme-readonly), shown and copyable on the token row. Not secret. - Client Secret — the token’s
mdc_…secret, shown only once at creation.
In Claude, open Settings → Connectors → Add custom connector, paste the Server URL, then enter the Client ID and Client Secret under Advanced / OAuth settings, and select Connect. The handshake is headless — no per-user login — and the connector is capped at the token’s scope and permission level. Revoking the token disables it immediately.
Tip: On the Integration Tokens page, each active token has an Add to Claude.ai action that opens a dialog with the Server URL, Client ID, and (right after creation) the secret, ready to copy.
See Getting Started with MCP for the full step-by-step.
Integration token (Bearer header)
For IDEs and CLI-based clients (Cursor, Claude Code, VS Code, Windsurf), create a token in the Meldoc web app and pass it to your MCP client as a Bearer header.
- Go to Settings → Integration Tokens → Create token.
- Copy the token (format:
mdc_...). - Add it to your Getting Started with MCP as a Bearer header (
Authorization: Bearer mdc_...).
You can also pass the token as an environment variable:
export MELDOC_ACCESS_TOKEN=mdc_your_token_here
OAuth 2.1 (Claude Desktop via mcp-remote)
When using mcp-remote for Claude Desktop, authentication happens automatically. On first connect, a browser window opens for secure login — no token needed. mcp-remote handles token refresh in the background.
When an assistant is asked to connect again
An OAuth connection keeps itself alive in the background: it trades its credential for a fresh one, and each trade replaces the old one rather than re-using it. Presenting a credential that has already been traded in ends the session immediately, and every assistant on it has to connect again.
That is a safeguard rather than a fault — it is how a leaked credential stops being useful — and it has one everyday consequence. A copied or restored setup disconnects the original. Restoring a machine from a backup, cloning a container image with the credentials baked in, or running one saved session on two machines all present a credential that was already spent, and the connection drops. Reconnect the assistant and it works again.
Revoking a token in Settings → Integration Tokens cuts it at once, with no wait for anything to expire.
Device flow (CLI / headless)
For headless environments without a browser. Your AI assistant can call auth_login_instructions to get step-by-step instructions for completing device code authentication.
Check authentication status
Your AI assistant can call server_info to see whether it is authenticated and what it may do — it answers with the account, the permissions and the server’s capabilities. There is no separate authentication-status tool.
Token loading priority
When the MCP server receives a request, it checks for a token in this order:
- Environment variable —
MELDOC_ACCESS_TOKENset in your shell (highest priority). - Saved session — credentials stored by OAuth or device-flow login, refreshed automatically when needed.
- Integration token variable —
MELDOC_MCP_TOKEN.
Security best practices
- Never commit tokens — add credential files to
.gitignore. - Rotate tokens periodically — use Create token for a new one, then Revoke Token on the old row in Settings → Integration Tokens.
- Scope your tokens — Integration Tokens let you control exactly what each token can access.
What’s next?
MCP Tools Reference — Available MCP tools.
Troubleshooting — Fix authentication issues.
Integration Tokens — Create scoped tokens for integrations.