Skip to content
API Reference

Quickstart

Run Claude Code in an audited Keycard session in minutes

By the end of this quickstart, you’ll have:

  • Claude Code running in a Keycard secure session, connected to an MCP server from the Catalog
  • A session log of the tool calls your agent makes

You should be able to complete this quickstart in about 10 minutes.

  1. Sign up for Keycard

    Go to console.keycard.ai, create your account, and sign in.

  2. Install the Keycard CLI

    Install the Keycard CLI from your computer’s terminal:

    Terminal window
    brew install keycardai/tap/keycard

    This gives you the keycard binary, Claude Code plugin, and a set of Skills Claude uses to manage your Keycard setup.

  3. Install the Keycard Claude plugin

    Terminal window
    claude plugin marketplace add keycardai/plugins
    claude plugin install keycard-cli@keycardai
  4. Install an MCP server from the catalog

    The Keycard Catalog lets you install official MCP servers like Linear, Sentry, Notion, Jira, GitHub, and more. Pick one to install:

    1. Open Console → Resources → Add Resource → Explore Resources.

    2. Pick a server (this quickstart uses Linear as the running example) and click Install. The server appears in your Resources list with a Keycard MCP Gateway URL.

    3. Open the installed resource, click Add to Coding Agent → Claude Code, and copy the displayed claude mcp add command into your terminal:

      Terminal window
      claude mcp add --transport http --scope user <server-name> <gateway-url>
  5. Run your agent in a secure session

    Find the CLI configuration snippet with your Organization ID and Zone ID in the Keycard Console:

    1. Open Settings → Connection, then copy the CLI configuration code block.

    2. In the root of your project, create a keycard.toml and paste your CLI configuration into the file:

      [org]
      id = "<org-id>"
      [zone]
      id = "<zone-id>"

    Then start a Keycard-protected Claude Code session:

    Terminal window
    keycard run -- claude
  6. Use the MCP server

    Ask Claude to do something that calls the MCP server you installed. For example, if you’re using Linear:

    List my open Linear issues.

    On the first call, Keycard prompts you to authorize access between Keycard and Linear:

    Keycard requesting access to Linear

    After you approve, Keycard provisions the credential for the session and Claude completes the request.

  7. Check the session log

    In your Keycard Console, click Sessions to see the tool calls made during your session with Claude.

Now that you have Claude Code running in a secure session with token exchange, here’s where to go next:

  • Install more MCP and API servers for Sentry, Notion, Atlassian, Gmail, Slack, and more in the Catalog
  • Access APIs on Behalf of Users so each agent call is scoped to the signed-in user’s identity, permissions, and audit attribution
  • Run Apps Without Static Secrets so workloads authorize every call with their own identity instead of long-lived API keys
  • Grant Agent Access to APIs so autonomous agents get their own scoped identity and audit trail, independent of any human
keycard run fails to start
  • Verify keycard auth signin succeeded by running keycard whoami
  • Check that keycard.toml exists in the project root and that its [org] id and [zone] id match the ones shown in Console under Settings → Connection
MCP server OAuth fails on first tool call
  • Open the application in Console → Applications and re-run the OAuth flow from the install dropdown
  • Confirm your claude mcp add command used the correct Gateway URL