Connect your AI assistant
The Bridge runs a hosted Model Context Protocol (MCP) server. Connect your AI assistant to it and the assistant can read and change your Bridge configuration for you: sign-in methods, workspaces and users, roles and privileges, plans and prices, feature flags and branding. It can also check that your integration actually works.
There is nothing to install and no API key to copy. You add the server URL to your client, sign in to The Bridge in your browser once, choose what the connection may reach, and approve.
Server details
Section titled “Server details”| Setting | Value |
|---|---|
| Server URL | https://api.thebridge.dev/mcp |
| Transport | Streamable HTTP (remote server) |
| Authentication | OAuth 2.0 authorization code flow with PKCE (S256). Dynamic client registration and client ID metadata documents are both supported, so clients register themselves. |
| Scopes | management, offline_access |
| Protected resource metadata | https://api.thebridge.dev/.well-known/oauth-protected-resource/mcp |
| Authorization server metadata | https://api.thebridge.dev/.well-known/oauth-authorization-server |
You need a Bridge account to approve the connection. If you don’t have one, choose Sign up when the browser opens: your account and first workspace are created in the same step, and the connection continues from there.
Connect your client
Section titled “Connect your client”Every client follows the same pattern: add the server URL, start the sign-in, then sign in and approve in the browser. See What you approve for what the approval screen asks.
Claude Code
Section titled “Claude Code”Run this in your project folder:
claude mcp add --transport http bridge https://api.thebridge.dev/mcp
- Start Claude Code and type
/mcp. Select bridge and choose to authenticate. - Your browser opens. Sign in (or sign up), choose your workspace and apps, and click Connect.
- Return to Claude Code.
/mcpnow shows bridge as connected.
The command adds the server to the current project. Add --scope user to make it available in every project:
claude mcp add --transport http --scope user bridge https://api.thebridge.dev/mcp
Claude (claude.ai and Claude Desktop)
Section titled “Claude (claude.ai and Claude Desktop)”Add The Bridge as a custom connector. Connectors you add on claude.ai are also available in Claude Desktop.
- Open Settings, then Connectors, and click Add custom connector.
- Enter
The Bridgeas the name andhttps://api.thebridge.dev/mcpas the remote MCP server URL. Click Add. - Click Connect next to The Bridge. Sign in (or sign up) in the window that opens, choose your workspace and apps, and click Connect.
- In a chat, enable The Bridge from the tools menu.
On a Team or Enterprise plan, an owner adds the connector once under the organization’s connector settings; members then only click Connect.
Leave the OAuth Client ID and OAuth Client Secret fields under Advanced settings empty. Claude registers itself. If your setup requires a fixed client ID, use claude with no secret.
Cursor
Section titled “Cursor”Add the server to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):
{
"mcpServers": {
"bridge": {
"url": "https://api.thebridge.dev/mcp"
}
}
}
- Open Cursor Settings, then MCP. Click Connect (or Needs login) next to bridge.
- Sign in (or sign up) in the browser, choose your workspace and apps, and click Connect.
If you need a fixed client ID instead of automatic registration, add "auth": { "CLIENT_ID": "cursor" } next to "url".
VS Code (GitHub Copilot)
Section titled “VS Code (GitHub Copilot)”Add the server to .vscode/mcp.json in your project:
{
"servers": {
"bridge": {
"type": "http",
"url": "https://api.thebridge.dev/mcp"
}
}
}
Or run MCP: Add Server from the Command Palette, choose HTTP, paste https://api.thebridge.dev/mcp and name it bridge.
- Start the server: click Start above the server entry in
mcp.json, or run MCP: List Servers, select bridge and choose Start Server. - VS Code asks to authenticate. Allow it, then sign in (or sign up) in the browser, choose your workspace and apps, and click Connect.
- Open Copilot Chat in Agent mode. The Bridge tools appear in the tools picker.
ChatGPT
Section titled “ChatGPT”Custom MCP connectors in ChatGPT require developer mode, which is available on Plus, Pro, Business, Enterprise and Education plans.
- In Settings, open Apps (under Advanced settings) and turn on Developer mode.
- Click Create app. Name it
The Bridge, enterhttps://api.thebridge.dev/mcpas the MCP server URL and choose OAuth as the authentication method. - Sign in (or sign up) in the browser, choose your workspace and apps, and click Connect.
- In a chat, choose Developer mode from the tools menu and enable The Bridge.
If ChatGPT asks for an OAuth client ID, use chatgpt and leave the secret empty.
Any other MCP client
Section titled “Any other MCP client”Any client that supports remote MCP servers over Streamable HTTP with OAuth can connect. Point it at https://api.thebridge.dev/mcp and let it discover the rest:
- An unauthenticated request to the server returns
401with aWWW-Authenticateheader pointing at the protected resource metadata. - The client reads the authorization server metadata, registers itself (dynamic client registration, or a client ID metadata document), and starts an authorization code flow with PKCE (
S256). - Request the
managementscope, plusoffline_accessif your client stores refresh tokens.
Clients without OAuth support can authenticate with an API token instead. See Use an API token instead.
What you approve
Section titled “What you approve”When you sign in, The Bridge shows an approval screen before anything is granted.
- Workspace. If you belong to more than one workspace, choose which one the connection works in. Click Change to pick another.
- Apps. Choose Every app in your workspace (selected by default; this includes apps you create later, and lets the assistant create apps) or Only one app. A connection to every app lets your assistant list your apps and switch between them without signing in again.
- What it can do. The connection can read and change your apps’ configuration: flags, plans, roles and login settings. It cannot delete anything.
- Where access is sent. The screen names the client and the address the approval is returned to, so you can check it is the client you meant to connect.
Click Connect to approve or Cancel to grant nothing.
Every request is checked against your own access at the moment it runs. If you leave the workspace or lose access to an app, the connection loses it too.
Your client receives a short-lived access token. Clients that requested offline_access renew it on their own, so you aren’t sent back to the browser every day. A connection that nobody uses for 30 days expires and needs a new sign-in.
Deletes are off unless you turn them on
Section titled “Deletes are off unless you turn them on”A connection approved in the browser never carries a delete privilege, so your assistant cannot delete a workspace, a user, a role, a privilege or a feature flag, and cannot revoke API tokens. If it tries, the call fails with a privilege error that tells it to send you to the dashboard instead.
To let an assistant delete, you have to grant it explicitly:
- In the Bridge dashboard, open Keys and create an API token. Tick the delete privileges you want to allow (for example
TENANT_DELETEorFLAG_DELETE). The dashboard marks these as destructive and warns you before creating the token. - Connect with that token, as described in Use an API token instead.
Even with the privilege, every delete has two more safeguards:
- Typed confirmation. A delete tool only runs when the call repeats the exact key of the thing being deleted. Your assistant is instructed to ask you first and not to fill this in on its own. Without it, nothing is deleted.
- Preview first. Delete tools accept a dry run that shows what would be affected and deletes nothing.
Every tool also declares MCP tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint), so clients that support them can ask you before a tool that changes or deletes something runs.
Use an API token instead
Section titled “Use an API token instead”Clients that can send a custom header can authenticate with an API token from the Keys page instead of signing in through the browser. The token covers one app and carries exactly the privileges you ticked when you created it. For example, in Claude Code:
claude mcp add --transport http bridge https://api.thebridge.dev/mcp \
--header "Authorization: Bearer YOUR_API_TOKEN"
Treat the token like a password. Don’t commit it to your repository, and revoke it on the Keys page when you no longer need it.
What your assistant can do
Section titled “What your assistant can do”The server exposes tools grouped by area. Read-only tools are marked as such; tools that change something are marked as writes.
| Area | What the assistant can do |
|---|---|
| Apps and environment | List the apps in your workspace, switch between them and create new ones. Read and update app settings, sign-in redirect URIs, the email sender, and environment details. |
| Sign-in methods | Read the login configuration. Turn on email and password, social login, passkeys, magic links and MFA, set up SSO, and set password rules. |
| Workspaces and users | List, read, create and update your customers’ workspaces (tenants). List, read and update users, and invite people. |
| Roles and privileges | List, create and update roles and privileges, and set the default role. |
| Plans, prices and limits | List, create and update plans; set and remove prices, usage limits (quotas) and the features a plan includes. Check Stripe status and connect Stripe. |
| Feature flags | List, read, create and update flags, turn them on or off, schedule changes, evaluate a flag for a given context, and export or import flags. Generate the code to read flags in your app. |
| Branding | Read and update the look of the sign-in and sign-up pages. |
| API tokens | List API tokens and the privileges they carry, and create tokens. |
| Guides and readiness checks | Get the integration guide for your framework, check your setup status, diagnose an integration, create a test user, run a real sign-in end to end, and explain why a user could not sign in. Read the event log. |
Delete tools (workspaces, users, roles, privileges, feature flags, token revocation) exist but only work with an explicitly granted privilege, as described above.
Guided prompts
Section titled “Guided prompts”The server also offers prompts that walk your assistant through a whole task with you. Your client lists them alongside the tools (in Claude Code, type / and look for the mcp__bridge__ entries):
| Prompt | What it does |
|---|---|
| Add login | Decide the sign-in experience, configure it and wire up the SDK. |
| Add a paid plan | Decide plans and prices, connect Stripe and show billing in your app. |
| Add a feature flag | Create a flag, decide its rules and read it in your app. |
| Add teams | Set up workspaces, invitations and roles, and wire them into your app. |
| Go live | Work through what still has to change before production. |
| Verify setup | Check the configuration against your project and sign in for real. |
| What is wrong | Find out why sign-in or the integration is failing, and what fixes it. |
Example prompts
Section titled “Example prompts”Once connected, ask in plain language. For example:
- “Add login to this app with The Bridge. I want email and password plus Google sign-in.”
- “Create a Pro plan at $20 a month with a limit of 5 projects, and connect Stripe.”
- “Create a feature flag called
new-dashboardthat is on only for workspaces on the Pro plan.” - “Add an Editor role that can edit content but can’t manage billing, and make it the default for new users.”
- “Check whether this app is ready to go live and tell me what’s missing.”
- “A user says they can’t sign in. Find out why.”
Troubleshooting
Section titled “Troubleshooting”The browser keeps asking me to sign in, or the connection never completes.
Finish the sign-in in a normal browser window. If the approval page says to open the link directly in your browser, copy the link out of the embedded view. If you closed the tab or the page shows an error, close it and start the connection again from your client (for example, /mcp in Claude Code, or Connect in the connector settings). Each attempt needs a fresh request from the client.
I connected the wrong workspace or app. Revoke the connection on the Keys page (see below), then connect again from your client. On the approval screen, click Change to pick the right workspace, and choose Every app in the workspace if your assistant needs more than one app. If the connection already covers every app, just ask your assistant to list your apps and switch to the right one.
A delete fails with a “privilege required” error. This is expected. Connections approved in the browser can’t delete anything. Do the delete in the dashboard, or connect with an API token that carries the delete privilege, as described in Deletes are off unless you turn them on.
A call fails with a confirmation error. Delete tools need the exact key of the resource repeated as confirmation. Check that the assistant picked the right resource, then confirm it when it asks you.
How do I disconnect or revoke access?
Open the Bridge dashboard and go to Keys. Under API Tokens, connections from AI assistants are labelled bridge-mcp. Click Revoke on the connection: it stops working immediately, including its ability to renew. Then remove the server from your client (for example, claude mcp remove bridge in Claude Code, or remove the connector in Claude’s or ChatGPT’s settings).
Privacy and support
Section titled “Privacy and support”The Bridge only receives the requests your assistant sends to the MCP server, such as “create a role called Editor”. It does not see your code or your conversation.
- Privacy policy: thebridge.dev/legal/privacy
- Terms of service: thebridge.dev/legal/terms
- Support: support@nebulr.group