Skip to main content
Use @kyberis-ai/mcp to connect MCP-capable agents to Kyberis tools. The setup flow uses a one-time connect token and normally installs direct API-key auth for the MCP connection. Install the Kyberis skill as well when your agent supports skills. The skill teaches the investigation workflow; MCP provides the callable tools.

Prerequisites

  • Node.js 20 or newer with npx
  • A one-time Kyberis connect token from API keys, beginning with kct_
  • A supported client: claude, codex, cursor, windsurf, or generic
  • The selected agent client installed locally, with its CLI available in PATH when you run npx

Connect a Client

Replace claude with your client name.
The command exchanges the token with Kyberis and configures supported clients by default.

Agent CLI Requirements

The connector configures local clients by invoking or updating the selected agent. For clients that use a CLI, that command must be installed and available in PATH in the same shell that runs npx. For Claude, install Claude Code from Anthropic’s quickstart, then verify:
On macOS, Linux, or WSL, Anthropic’s installer is:
On Windows PowerShell:

How MCP Access Works

MCP setup uses several related objects: The one-command setup creates or selects an API key with the scopes available to your account, installs it in the local MCP client when the secret is returned, and records the server-side association for tracking and brokered MCP flows. If a tool later returns insufficient_scope, check missing_scopes and required_scopes, then create or update an API key with those scopes and reconnect the MCP client from API keys so its local credential is updated. Changing API key scopes or the server-side association does not update local MCP client configuration by itself. Reconnect MCP after changing scopes or rotating keys so direct API-key clients use the current credential.
The setup command may show an api_key_id or API Key ID. When api_key_secret_retrievable is true, the connector installed direct API-key auth for the MCP client. When it is false, the exchange used a legacy bearer fallback and the API key secret cannot be retrieved later. Rebinding in the dashboard does not rewrite an agent’s local direct API-key header; reconnect the client to install a new credential. To call the REST API directly outside MCP, create a separate API key in the Kyberis dashboard and save its secret when it is shown.

Options

Use --print-config when you want manual installation guidance without changing local client config.
--dry-run and -n are compatibility aliases for --print-config. These modes still exchange and spend the one-time connect token, register the MCP client, and create server-side credentials; they only skip local client configuration changes. Use --json when you need machine-readable connection details. --json does not change local client config, but it also exchanges and spends the connect token.

Default Configuration Targets

For supported clients, @kyberis-ai/mcp updates the local MCP configuration by default: For Claude Code, --scope local means the Kyberis MCP server is available only in the current project directory. Use --scope user if you want Kyberis available across all Claude Code projects for your OS user. Use --scope project only when you intentionally want shared project configuration, and never commit API keys, bearer fallback tokens, or other secrets.

What the Command Returns

The setup command returns:
  • agent_id: the registered agent identity
  • mcp_url: the MCP endpoint URL
  • api_key_id: the API key associated with this agent connection
  • auth_mode: api_key for the normal direct API-key path, or bearer_fallback for legacy exchange responses
  • api_key_secret_retrievable: whether the setup response included the API key secret used for direct API-key auth
  • Authorization: ApiKey <key_id>:<secret> header for the MCP client, or a bearer fallback header for older exchange responses
  • client-specific configuration for Claude, Codex, Cursor, Windsurf, or generic MCP clients

Token Errors

Generate a new connect token from API keys when setup returns one of these conditions:

After Connecting

Run a simple prompt in your agent:
The agent should call Kyberis tools through MCP and preserve request IDs in any error report.