Skip to content

Connect your AI assistant

The Bridge runs a hosted Model Context Protocol (MCP) server. Connect your AI assistant to it and the assistant can read and change your Bridge configuration for you: sign-in methods, workspaces and users, roles and privileges, plans and prices, feature flags and branding. It can also check that your integration actually works.

There is nothing to install and no API key to copy. You add the server URL to your client, sign in to The Bridge in your browser once, choose what the connection may reach, and approve.

SettingValue
Server URLhttps://api.thebridge.dev/mcp
TransportStreamable HTTP (remote server)
AuthenticationOAuth 2.0 authorization code flow with PKCE (S256). Dynamic client registration and client ID metadata documents are both supported, so clients register themselves.
Scopesmanagement, offline_access
Protected resource metadatahttps://api.thebridge.dev/.well-known/oauth-protected-resource/mcp
Authorization server metadatahttps://api.thebridge.dev/.well-known/oauth-authorization-server

You need a Bridge account to approve the connection. If you don’t have one, choose Sign up when the browser opens: your account and first workspace are created in the same step, and the connection continues from there.

Every client follows the same pattern: add the server URL, start the sign-in, then sign in and approve in the browser. See What you approve for what the approval screen asks.

Run this in your project folder:

claude mcp add --transport http bridge https://api.thebridge.dev/mcp
  1. Start Claude Code and type /mcp. Select bridge and choose to authenticate.
  2. Your browser opens. Sign in (or sign up), choose your workspace and apps, and click Connect.
  3. Return to Claude Code. /mcp now shows bridge as connected.

The command adds the server to the current project. Add --scope user to make it available in every project:

claude mcp add --transport http --scope user bridge https://api.thebridge.dev/mcp

Add The Bridge as a custom connector. Connectors you add on claude.ai are also available in Claude Desktop.

  1. Open Settings, then Connectors, and click Add custom connector.
  2. Enter The Bridge as the name and https://api.thebridge.dev/mcp as the remote MCP server URL. Click Add.
  3. Click Connect next to The Bridge. Sign in (or sign up) in the window that opens, choose your workspace and apps, and click Connect.
  4. In a chat, enable The Bridge from the tools menu.

On a Team or Enterprise plan, an owner adds the connector once under the organization’s connector settings; members then only click Connect.

Leave the OAuth Client ID and OAuth Client Secret fields under Advanced settings empty. Claude registers itself. If your setup requires a fixed client ID, use claude with no secret.

Add the server to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

{
  "mcpServers": {
    "bridge": {
      "url": "https://api.thebridge.dev/mcp"
    }
  }
}
  1. Open Cursor Settings, then MCP. Click Connect (or Needs login) next to bridge.
  2. Sign in (or sign up) in the browser, choose your workspace and apps, and click Connect.

If you need a fixed client ID instead of automatic registration, add "auth": { "CLIENT_ID": "cursor" } next to "url".

Add the server to .vscode/mcp.json in your project:

{
  "servers": {
    "bridge": {
      "type": "http",
      "url": "https://api.thebridge.dev/mcp"
    }
  }
}

Or run MCP: Add Server from the Command Palette, choose HTTP, paste https://api.thebridge.dev/mcp and name it bridge.

  1. Start the server: click Start above the server entry in mcp.json, or run MCP: List Servers, select bridge and choose Start Server.
  2. VS Code asks to authenticate. Allow it, then sign in (or sign up) in the browser, choose your workspace and apps, and click Connect.
  3. Open Copilot Chat in Agent mode. The Bridge tools appear in the tools picker.

Custom MCP connectors in ChatGPT require developer mode, which is available on Plus, Pro, Business, Enterprise and Education plans.

  1. In Settings, open Apps (under Advanced settings) and turn on Developer mode.
  2. Click Create app. Name it The Bridge, enter https://api.thebridge.dev/mcp as the MCP server URL and choose OAuth as the authentication method.
  3. Sign in (or sign up) in the browser, choose your workspace and apps, and click Connect.
  4. In a chat, choose Developer mode from the tools menu and enable The Bridge.

If ChatGPT asks for an OAuth client ID, use chatgpt and leave the secret empty.

Any client that supports remote MCP servers over Streamable HTTP with OAuth can connect. Point it at https://api.thebridge.dev/mcp and let it discover the rest:

  1. An unauthenticated request to the server returns 401 with a WWW-Authenticate header pointing at the protected resource metadata.
  2. The client reads the authorization server metadata, registers itself (dynamic client registration, or a client ID metadata document), and starts an authorization code flow with PKCE (S256).
  3. Request the management scope, plus offline_access if your client stores refresh tokens.

Clients without OAuth support can authenticate with an API token instead. See Use an API token instead.

When you sign in, The Bridge shows an approval screen before anything is granted.

  • Workspace. If you belong to more than one workspace, choose which one the connection works in. Click Change to pick another.
  • Apps. Choose Every app in your workspace (selected by default; this includes apps you create later, and lets the assistant create apps) or Only one app. A connection to every app lets your assistant list your apps and switch between them without signing in again.
  • What it can do. The connection can read and change your apps’ configuration: flags, plans, roles and login settings. It cannot delete anything.
  • Where access is sent. The screen names the client and the address the approval is returned to, so you can check it is the client you meant to connect.

Click Connect to approve or Cancel to grant nothing.

Every request is checked against your own access at the moment it runs. If you leave the workspace or lose access to an app, the connection loses it too.

Your client receives a short-lived access token. Clients that requested offline_access renew it on their own, so you aren’t sent back to the browser every day. A connection that nobody uses for 30 days expires and needs a new sign-in.

A connection approved in the browser never carries a delete privilege, so your assistant cannot delete a workspace, a user, a role, a privilege or a feature flag, and cannot revoke API tokens. If it tries, the call fails with a privilege error that tells it to send you to the dashboard instead.

To let an assistant delete, you have to grant it explicitly:

  1. In the Bridge dashboard, open Keys and create an API token. Tick the delete privileges you want to allow (for example TENANT_DELETE or FLAG_DELETE). The dashboard marks these as destructive and warns you before creating the token.
  2. Connect with that token, as described in Use an API token instead.

Even with the privilege, every delete has two more safeguards:

  • Typed confirmation. A delete tool only runs when the call repeats the exact key of the thing being deleted. Your assistant is instructed to ask you first and not to fill this in on its own. Without it, nothing is deleted.
  • Preview first. Delete tools accept a dry run that shows what would be affected and deletes nothing.

Every tool also declares MCP tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint), so clients that support them can ask you before a tool that changes or deletes something runs.

Clients that can send a custom header can authenticate with an API token from the Keys page instead of signing in through the browser. The token covers one app and carries exactly the privileges you ticked when you created it. For example, in Claude Code:

claude mcp add --transport http bridge https://api.thebridge.dev/mcp \
  --header "Authorization: Bearer YOUR_API_TOKEN"

Treat the token like a password. Don’t commit it to your repository, and revoke it on the Keys page when you no longer need it.

The server exposes tools grouped by area. Read-only tools are marked as such; tools that change something are marked as writes.

AreaWhat the assistant can do
Apps and environmentList the apps in your workspace, switch between them and create new ones. Read and update app settings, sign-in redirect URIs, the email sender, and environment details.
Sign-in methodsRead the login configuration. Turn on email and password, social login, passkeys, magic links and MFA, set up SSO, and set password rules.
Workspaces and usersList, read, create and update your customers’ workspaces (tenants). List, read and update users, and invite people.
Roles and privilegesList, create and update roles and privileges, and set the default role.
Plans, prices and limitsList, create and update plans; set and remove prices, usage limits (quotas) and the features a plan includes. Check Stripe status and connect Stripe.
Feature flagsList, read, create and update flags, turn them on or off, schedule changes, evaluate a flag for a given context, and export or import flags. Generate the code to read flags in your app.
BrandingRead and update the look of the sign-in and sign-up pages.
API tokensList API tokens and the privileges they carry, and create tokens.
Guides and readiness checksGet the integration guide for your framework, check your setup status, diagnose an integration, create a test user, run a real sign-in end to end, and explain why a user could not sign in. Read the event log.

Delete tools (workspaces, users, roles, privileges, feature flags, token revocation) exist but only work with an explicitly granted privilege, as described above.

The server also offers prompts that walk your assistant through a whole task with you. Your client lists them alongside the tools (in Claude Code, type / and look for the mcp__bridge__ entries):

PromptWhat it does
Add loginDecide the sign-in experience, configure it and wire up the SDK.
Add a paid planDecide plans and prices, connect Stripe and show billing in your app.
Add a feature flagCreate a flag, decide its rules and read it in your app.
Add teamsSet up workspaces, invitations and roles, and wire them into your app.
Go liveWork through what still has to change before production.
Verify setupCheck the configuration against your project and sign in for real.
What is wrongFind out why sign-in or the integration is failing, and what fixes it.

Once connected, ask in plain language. For example:

  • “Add login to this app with The Bridge. I want email and password plus Google sign-in.”
  • “Create a Pro plan at $20 a month with a limit of 5 projects, and connect Stripe.”
  • “Create a feature flag called new-dashboard that is on only for workspaces on the Pro plan.”
  • “Add an Editor role that can edit content but can’t manage billing, and make it the default for new users.”
  • “Check whether this app is ready to go live and tell me what’s missing.”
  • “A user says they can’t sign in. Find out why.”

The browser keeps asking me to sign in, or the connection never completes. Finish the sign-in in a normal browser window. If the approval page says to open the link directly in your browser, copy the link out of the embedded view. If you closed the tab or the page shows an error, close it and start the connection again from your client (for example, /mcp in Claude Code, or Connect in the connector settings). Each attempt needs a fresh request from the client.

I connected the wrong workspace or app. Revoke the connection on the Keys page (see below), then connect again from your client. On the approval screen, click Change to pick the right workspace, and choose Every app in the workspace if your assistant needs more than one app. If the connection already covers every app, just ask your assistant to list your apps and switch to the right one.

A delete fails with a “privilege required” error. This is expected. Connections approved in the browser can’t delete anything. Do the delete in the dashboard, or connect with an API token that carries the delete privilege, as described in Deletes are off unless you turn them on.

A call fails with a confirmation error. Delete tools need the exact key of the resource repeated as confirmation. Check that the assistant picked the right resource, then confirm it when it asks you.

How do I disconnect or revoke access? Open the Bridge dashboard and go to Keys. Under API Tokens, connections from AI assistants are labelled bridge-mcp. Click Revoke on the connection: it stops working immediately, including its ability to renew. Then remove the server from your client (for example, claude mcp remove bridge in Claude Code, or remove the connector in Claude’s or ChatGPT’s settings).

The Bridge only receives the requests your assistant sends to the MCP server, such as “create a role called Editor”. It does not see your code or your conversation.