Point any MCP-capable AI client at the hosted MCP server and drive Indexhog over OAuth — no token to paste.
5 min readIndexhog runs a hosted, remote Model Context Protocol (MCP) server. Point an MCP-capable client at one URL, sign in once, and your agent can manage projects, organizations, and billing through the same API the dashboard uses. The server is an OAuth 2.1 resource server — you authorize in the browser, so there is no API key to copy or store.
You need: an account and an MCP-capable client (Claude Desktop, Claude Code, Cursor, VS Code,
or anything that speaks MCP over HTTP). The MCP endpoint is https://mcp.indexhog.com.
Add this server to your client. On first use the client opens a browser window for you to sign in and authorize — the OAuth 2.1 + PKCE handshake (discovery, dynamic registration, token exchange) happens automatically.
{
"mcpServers": {
"indexhog": {
"url": "https://mcp.indexhog.com"
}
}
}MCP does not accept tkn_ personal access tokens. PATs are for the REST API only (sent on the
X-Api-Key header). The MCP server authenticates with an OAuth access token that the client
obtains for you. If you put a PAT in the Authorization header, the server returns 401.
Inspect the REST surface that backs the MCP tools:
Open Settings → Connectors → Add custom connector, give it a name, and paste the server URL:
https://mcp.indexhog.comClaude prompts you to sign in and authorize on first use. The tools then appear in the connector list.
Add the server from the CLI as a streamable-HTTP transport:
claude mcp add --transport http indexhog https://mcp.indexhog.comRun /mcp inside Claude Code to trigger the browser sign-in, then confirm the server shows as
connected.
Add it to your project's .cursor/mcp.json (or the global ~/.cursor/mcp.json):
{
"mcpServers": {
"indexhog": {
"url": "https://mcp.indexhog.com"
}
}
}Open Settings → MCP, confirm the server is listed, and complete the sign-in when prompted.
Register the server with the CLI:
code --add-mcp '{"name":"indexhog","url":"https://mcp.indexhog.com"}'Or add it to .vscode/mcp.json using the same shape as the Cursor example above.
Clients that only speak stdio can bridge to the remote server with mcp-remote:
{
"mcpServers": {
"indexhog": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://mcp.indexhog.com"]
}
}
}The server implements OAuth 2.1 + PKCE with dynamic client registration (RFC 7591) and exposes protected-resource metadata (RFC 9728), so compliant clients discover everything they need from the URL alone.
GET https://mcp.indexhog.com/.well-known/oauth-protected-resource returns the
authorization server (https://api.indexhog.com/api/auth).Authorization: Bearer <jwt>
on every call.401 always carries a WWW-Authenticate: Bearer … header pointing
at the resource-metadata URL, so clients re-authorize automatically.The MCP server exposes the agent-callable subset of the external contract as tools, grouped below. The live, always-current
list is whatever your client's tools/list returns — treat that as the source of truth and follow
the linked references for full arguments and responses.
| Group | Reference |
|---|---|
Projects & inventory (list_user_projects, create_project, list_project_urls, get_project_stats) | Projects |
Verification (get_project_verification, verify_project_dns) | Projects |
Issues & engines (list_project_issues, connect_project_bing, get_project_gsc_o_auth_url) | Projects |
Organizations & members (list_user_organizations, create_organization, create_organization_invites, update_organization_member_role) | Organizations |
SSO & MFA (get_organization_sso_config, update_organization_sso_config, update_organization_mfa_settings) | Enterprise SSO |
Billing (create_checkout_session, get_billing_settings) | Payments |
User & account (get_current_user, export_user_data) | User |
API-key management and other auth-tier operations remain REST/session-only. External documentation does not automatically make an operation an MCP tool.
Set organization context first. Most tools are scoped to an organization. Call
get_current_user, then list_user_organizations to pick the target org, before running
org-scoped tools — skipping this is the most common first-run error
(TENANT_CONTEXT_MISSING).
The product skill packages everything an agent needs to drive Indexhog — connection rules, org-context flow, pagination and response-envelope conventions, tool disambiguation, and step-by-step workflows. Install it alongside the MCP server for far fewer first-run mistakes.
To install in Claude Code, unzip into your skills directory:
mkdir -p ~/.claude/skills
unzip product-skill.zip -d ~/.claude/skills
# → ~/.claude/skills/product/SKILL.mdFor claude.ai, upload the unchanged product-skill.zip in Settings → Capabilities → Skills.
| Symptom | Cause | Fix |
|---|---|---|
401 Unauthorized | No token, expired session, or a tkn_ PAT on the MCP server | Re-run the client's sign-in; MCP needs an OAuth token, not a PAT |
TENANT_CONTEXT_MISSING / NOT_ORGANIZATION_MEMBER | Called an org-scoped tool without choosing an org | Run list_user_organizations and pass that org's id |
429 Too Many Requests | Rate limit hit | Honor Retry-After before retrying |
| Client can't connect | Wrong URL or stdio-only client | Use https://mcp.indexhog.com; bridge stdio clients with mcp-remote |
tkn_ PAT on the REST API.offset/limit pagination, the response envelope) that agents otherwise learn by failing.How the API is structured, how authentication works, and how multi-tenant requests are scoped
Sign in, issue a Personal Access Token, and make your first authenticated call
Request headers, response envelope, pagination, and the query conventions shared by every endpoint
Error envelope, full code list, and the retry strategies that actually work