opsen
opsen

MCP server

Start runs from Claude Code, Cursor or anything else that speaks MCP.

claude mcp add --transport http --scope user opsen \
  https://opsen.dev/mcp \
  --header "Authorization: Bearer YOUR_OPSEN_KEY"

Connecting without a key

A client that supports OAuth can connect without you pasting anything. It registers itself, sends you to opsen to approve, and receives a token scoped to your account:

endpointwhat it is
/.well-known/oauth-protected-resourcewhich server guards /mcp
/.well-known/oauth-authorization-serverthe server's metadata
/oauth/registerdynamic registration — no pre-shared client id
/oauth/authorizethe consent screen
/oauth/tokencode for token, PKCE required

The token you get back is an opsen API key. It shows up on your keys page labelled with the application that requested it, and you revoke it there like any other. Disconnecting an app is revoking its key.

A registration survives restarts and deploys, so an application you connected stays connected. Registrations older than ninety days are dropped, and a client that has not been used since simply registers again.

Only the authorization code flow with an S256 challenge is accepted. No implicit grant, no client secrets, no plain challenges — all three were removed in OAuth 2.1 and all three exist because 2010 did not have PKCE.

Tools

tooldoes
runrun a script or a repo, return output and cost
openopen a sandbox and keep it
execrun a command in an open sandbox
write / readmove files in and out
closestop a sandbox
listwhat is open right now
taskssaved tasks
run_manya task over many inputs
credentialswhat can be lent to a run
costwhat a run cost

Why this matters more than it looks

An assistant that can run code somewhere isolated is a different thing from one that can only suggest it. The tools are annotated with whether they are read-only and whether they destroy anything, so the client can ask before doing the second kind.

Discovery is open; execution is authenticated. Listing the tools tells an attacker nothing they could not read here. Calling one requires your key.