Code editors and CLI agents

Code editors and command-line agents take the server URL and a token in a header. Issue a token on your profile page - one per tool, so any of them can be cut off alone - and keep it out of files you commit.

In the examples the token is read from the environment variable PUBLICWWW_TOKEN, or asked for once; where a client cannot do either, YOUR_TOKEN stands for the token itself. Claude Code is on the Claude page.

VS Code

GitHub Copilot's agent mode. Add to .vscode/mcp.json in the project, or to the user configuration (command palette: MCP: Open User Configuration):

{
  "inputs": [
    { "type": "promptString", "id": "publicwww-token",
      "description": "PublicWWW token", "password": true }
  ],
  "servers": {
    "publicwww": {
      "type": "http",
      "url": "https://api.publicwww.com/mcp",
      "headers": { "Authorization": "Bearer ${input:publicwww-token}" }
    }
  }
}

VS Code asks for the token the first time the server starts and stores it in its secret storage, not in the file. The same in one click: Install in VS Code.

Cursor

~/.cursor/mcp.json for every project, or .cursor/mcp.json in one:

{
  "mcpServers": {
    "publicwww": {
      "url": "https://api.publicwww.com/mcp",
      "headers": { "Authorization": "Bearer ${env:PUBLICWWW_TOKEN}" }
    }
  }
}

Or in one click: Add to Cursor - it reads the token from PUBLICWWW_TOKEN.

Devin Desktop (formerly Windsurf)

~/.config/devin/mcp_config.json, on Windows %APPDATA%\devin\mcp_config.json:

{
  "mcpServers": {
    "publicwww": {
      "url": "https://api.publicwww.com/mcp",
      "headers": { "Authorization": "Bearer YOUR_TOKEN" }
    }
  }
}

Use url: the older serverUrl is understood only by the previous Cascade agent.

Gemini CLI

As an extension - it asks for the token once, keeps it in the system keychain and brings a skill with the query syntax:

gemini extensions install https://github.com/publicwww-com/publicwww-mcp

Or by hand in ~/.gemini/settings.json - the key for a Streamable HTTP server is httpUrl:

{
  "mcpServers": {
    "publicwww": {
      "httpUrl": "https://api.publicwww.com/mcp",
      "headers": { "Authorization": "Bearer ${PUBLICWWW_TOKEN}" }
    }
  }
}

url instead of httpUrl would make Gemini CLI speak the older SSE transport, which this server does not serve.

Codex CLI

codex mcp add publicwww --url https://api.publicwww.com/mcp \
     --bearer-token-env-var PUBLICWWW_TOKEN

or the same by hand in ~/.codex/config.toml; Codex reads the token from the variable it is told to:

[mcp_servers.publicwww]
url = "https://api.publicwww.com/mcp"
bearer_token_env_var = "PUBLICWWW_TOKEN"

Codex can also sign in with OAuth instead of a token:

codex mcp add publicwww --url https://api.publicwww.com/mcp
codex mcp login publicwww

Codex on a server over SSH. After you press Allow, the browser is sent to http://127.0.0.1:<port>/callback?code=… - an address only Codex itself listens on, on the server, so your browser shows a connection error. Copy that whole address from the address bar and, while codex mcp login is still waiting, open it on the server:

curl "http://127.0.0.1:<port>/callback?code=...&state=..."

Codex reports the sign-in as done. The code works once and for ten minutes, and the address has to come from the same codex mcp login run.

DeepSeek Harness

dsh plugin --profile web add github:publicwww-com/dsh-publicwww

The plugin connects the server through DeepSeek Harness's own MCP client and reads the token from PUBLICWWW_TOKEN - see the plugin page.

Anything else

Any client that can add a remote MCP server over Streamable HTTP and set a request header will work with the URL and the Authorization: Bearer header. A client that only starts local servers can reach this one through the mcp-remote bridge (needs Node.js):

{
  "mcpServers": {
    "publicwww": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://api.publicwww.com/mcp",
               "--header", "Authorization:${AUTH_HEADER}"],
      "env": { "AUTH_HEADER": "Bearer YOUR_TOKEN" }
    }
  }
}

Ready-made files for all of these, an agent skill with the query syntax and the install buttons are on GitHub.

No space after Authorization: on purpose: some clients pass arguments with spaces in them incorrectly, so the part with the space lives in env.

Next Tools