By the end of this quickstart, you’ll have:
- Claude Code running in a Keycard secure session, connected to an MCP server from the Catalog
- A session log of the tool calls your agent makes
You should be able to complete this quickstart in about 10 minutes.
-
Sign up for Keycard
Go to console.keycard.ai, create your account, and sign in.
-
Install the Keycard CLI
Install the Keycard CLI from your computer’s terminal:
Terminal window brew install keycardai/tap/keycardThis gives you the
keycardbinary, Claude Code plugin, and a set of Skills Claude uses to manage your Keycard setup. -
Install the Keycard Claude plugin
Terminal window claude plugin marketplace add keycardai/pluginsclaude plugin install keycard-cli@keycardai -
Install an MCP server from the catalog
The Keycard Catalog lets you install official MCP servers like Linear, Sentry, Notion, Jira, GitHub, and more. Pick one to install:
-
Open Console → Resources → Add Resource → Explore Resources.
-
Pick a server (this quickstart uses Linear as the running example) and click Install. The server appears in your Resources list with a Keycard MCP Gateway URL.
-
Open the installed resource, click Add to Coding Agent → Claude Code, and copy the displayed
claude mcp addcommand into your terminal:Terminal window claude mcp add --transport http --scope user <server-name> <gateway-url>
-
-
Run your agent in a secure session
Find the CLI configuration snippet with your Organization ID and Zone ID in the Keycard Console:
-
Open Settings → Connection, then copy the CLI configuration code block.
-
In the root of your project, create a
keycard.tomland paste your CLI configuration into the file:[org]id = "<org-id>"[zone]id = "<zone-id>"
Then start a Keycard-protected Claude Code session:
Terminal window keycard run -- claude -
-
Use the MCP server
Ask Claude to do something that calls the MCP server you installed. For example, if you’re using Linear:
List my open Linear issues.
On the first call, Keycard prompts you to authorize access between Keycard and Linear:

After you approve, Keycard provisions the credential for the session and Claude completes the request.
-
Check the session log
In your Keycard Console, click Sessions to see the tool calls made during your session with Claude.
What’s Next
Section titled “What’s Next”Now that you have Claude Code running in a secure session with token exchange, here’s where to go next:
- Install more MCP and API servers for Sentry, Notion, Atlassian, Gmail, Slack, and more in the Catalog
- Access APIs on Behalf of Users so each agent call is scoped to the signed-in user’s identity, permissions, and audit attribution
- Run Apps Without Static Secrets so workloads authorize every call with their own identity instead of long-lived API keys
- Grant Agent Access to APIs so autonomous agents get their own scoped identity and audit trail, independent of any human
Troubleshooting
Section titled “Troubleshooting”keycard run fails to start
- Verify
keycard auth signinsucceeded by runningkeycard whoami - Check that
keycard.tomlexists in the project root and that its[org] idand[zone] idmatch the ones shown in Console under Settings → Connection
MCP server OAuth fails on first tool call
- Open the application in Console → Applications and re-run the OAuth flow from the install dropdown
- Confirm your
claude mcp addcommand used the correct Gateway URL