# Quickstart

By the end of this quickstart, you'll have:

- Claude Code running in a Keycard secure session, connected to an MCP server from the Catalog
- A session log of the tool calls your agent makes

You should be able to complete this quickstart in about 10 minutes.

> **Note:** This quickstart uses [Claude Code](https://code.claude.com/docs/en/overview) and the Keycard CLI. If you're not using the CLI, see [SDK guides](/guides/#use-the-sdk) for manual setup. If you use Cursor or another MCP-compatible agent, Console's **Add to Coding Agent** option supports other coding agents too.

1. **Sign up for Keycard**

   Go to [console.keycard.ai](https://console.keycard.ai), create your account, and sign in.

   > **Note:** Keycard is currently in Early Access. You can [sign up here](https://keycard.ai/pricing).

2. **Install the Keycard CLI**

   Install the Keycard CLI from your computer's terminal:

   ```bash
   brew install keycardai/tap/keycard
   ```

   This gives you the `keycard` binary, Claude Code plugin, and a set of [Skills](/skills/) Claude uses to manage your Keycard setup.

3. **Install the Keycard Claude plugin**

    ```bash
    claude plugin marketplace add keycardai/plugins
    claude plugin install keycard-cli@keycardai
    ```

4. **Install an MCP server from the catalog**

   The Keycard [Catalog](/admin/catalog/) lets you install official MCP servers like Linear, Sentry, Notion, Jira, GitHub, and more. Pick one to install:
   1. Open [Console](https://console.keycard.ai) → **Resources** → **Add Resource** → **Explore Resources**.
   2. Pick a server (this quickstart uses **Linear** as the running example) and click **Install**. The server appears in your **Resources** list with a Keycard MCP Gateway URL.
   3. Open the installed resource, click **Add to Coding Agent** → **Claude Code**, and copy the displayed `claude mcp add` command into your terminal:

      ```bash
      claude mcp add --transport http --scope user <server-name> <gateway-url>
      ```

   > **Tip:** Want to install to Cursor or another client instead of Claude Code? The **Add to Coding Agent** dropdown in Console lists every supported client.

5. **Run your agent in a secure session**

   Find the CLI configuration snippet with your **Organization ID** and **Zone ID** in the [Keycard Console](https://console.keycard.ai):

   1. Open **Settings** → **Connection**, then copy the **CLI configuration** code block.
   
   2. In the root of your project, create a `keycard.toml` and paste your CLI configuration into the file:

      ```toml
      [org]
      id = "<org-id>"
      
      [zone]
      id = "<zone-id>"
      ```

   Then start a Keycard-protected Claude Code session:

   ```bash
   keycard run -- claude
   ```

6. **Use the MCP server**

   Ask Claude to do something that calls the MCP server you installed. For example, if you're using Linear:

   > List my open Linear issues.

   On the first call, Keycard prompts you to authorize access between Keycard and Linear:

   ![Keycard requesting access to Linear](./images/keycard-linear-authorization.png)

   After you approve, Keycard provisions the credential for the session and Claude completes the request.

7. **Check the session log**

   In your [Keycard Console](https://console.keycard.ai), click **Sessions** to see the tool calls made during your session with Claude.

## What's Next

Now that you have Claude Code running in a secure session with token exchange, here's where to go next:

- **Install more MCP and API servers** for Sentry, Notion, Atlassian, Gmail, Slack, and more in the [Catalog](/admin/catalog/)
- **[Access APIs on Behalf of Users](/guides/access-apis-on-behalf-of-users/)** so each agent call is scoped to the signed-in user's identity, permissions, and audit attribution
- **[Run Apps Without Static Secrets](/guides/run-apps-without-static-secrets/)** so workloads authorize every call with their own identity instead of long-lived API keys
- **[Grant Agent Access to APIs](/guides/grant-agent-access-to-apis/)** so autonomous agents get their own scoped identity and audit trail, independent of any human

## Troubleshooting

<details>
<summary>`keycard run` fails to start</summary>
- Verify `keycard auth signin` succeeded by running `keycard whoami`
- Check that `keycard.toml` exists in the project root and that its `[org] id` and `[zone] id` match the ones shown in Console under **Settings** → **Connection**
</details>

<details>
<summary>MCP server OAuth fails on first tool call</summary>
- Open the application in [Console](https://console.keycard.ai) → **Applications** and re-run the OAuth flow from the install dropdown
- Confirm your `claude mcp add` command used the correct Gateway URL
</details>
