Connect an AI client
OIDA Cloud is a remote MCP server over Streamable HTTP with OAuth 2.1. Any client that supports both can connect. These are the paths verified so far.
What every client needs
- Streamable HTTP transport (MCP 2025-11-25). The endpoint answers POST. GET and DELETE return 405.
- OAuth 2.1 with PKCE and dynamic client registration. The client discovers the authorisation server from the protected-resource metadata and registers itself. OIDA hands out no client credentials and no long-lived tokens.
- A browser for the sign-in and consent page. Consent names the client, your account and the workspace.
Clients that can only send a static bearer header cannot connect. Status per client: Tested means a real run completed end to end. Documented follows the vendor’s published set-up path and has not yet been run against OIDA Cloud.
Clients
ChatGPT (developer mode) Documented
- In ChatGPT on the web, open Settings → Security and login and turn on Developer mode (Pro, Plus, Business, Enterprise and Edu accounts. On Business, Enterprise and Edu an admin enables it in workspace settings first).
- Open ChatGPT Plugins, select the plus button, choose Connection → Public endpoint and enter the workspace endpoint URL including its /mcp/<slug> path.
- Choose OAuth as the authentication method. ChatGPT registers itself with the OIDA authorization server and opens the OIDA sign-in and consent page. Approve the connection.
- Review the discovered tools. Read tools are marked read-only. Ingest, ontology edits and governance actions ask for confirmation before they run.
- OpenAI developer documentation lists read and write tools for eligible developer-mode accounts on the web. Availability can depend on your workspace controls; verify the tools shown in your account. OIDA does not provide the search/fetch tools required by deep-research connectors.
Claude (web, desktop and mobile) Documented
- Free, Pro and Max: open Customize → Connectors and click "Add custom connector". Team and Enterprise: an Owner adds it under Organization settings → Connectors → Add → Custom → Web. Members then click Connect.
- Enter a name and the workspace endpoint URL exactly as shown above (no trailing slash). Leave the OAuth client on automatic registration: OIDA does not publish client-ID metadata documents, so Claude registers itself dynamically.
- Click Add, then Connect. Sign in to OIDA in the browser window and approve the consent page, which lists the requesting client, your account and your workspaces.
- In a chat, open the + menu → Connectors and enable OIDA. Tool permissions can be blocked per tool under Customize → Connectors.
- Limits: Free accounts get one custom connector. Connectors are not available in Claude Desktop WSL sessions. Authentication settings cannot be edited after adding (remove and re-add).
Claude Code Tested
- Run the command below in your project (add --scope project to share the server through .mcp.json. The "type": "http" key is mandatory in that file).
- Run "claude mcp login oida" or, inside a session, /mcp → oida → Authenticate. The browser opens the OIDA sign-in page and then the consent page. Approve.
- Tools appear as mcp__oida__<tool>. Claude Code refreshes tokens automatically and retries once on 401. "! Needs authentication" in /mcp means a new login is needed.
- Not yet verified: Claude Code normally identifies itself with its own client-ID metadata document, which the OIDA authorization server does not support. Dynamic registration with a loopback callback is the expected fallback.
claude mcp add --transport http oida https://mcp.projectoida.com/mcp/<your-workspace>
claude mcp login oidaCursor Tested
- Add the server below to the project file .cursor/mcp.json or the global file ~/.cursor/mcp.json (the transport is detected from the url).
- Open Cursor Settings → MCP and click the login action shown for oida. Sign in to OIDA in the browser and approve the consent page. The server then turns green and lists its tools.
- Cursor registers itself dynamically with the OIDA authorization server using its fixed callbacks (www.cursor.com/agents/mcp/oauth/callback and localhost:8787). The CLI equivalents are "agent mcp list" and "agent mcp login oida".
- Limits: the documented "headers" option needs a long-lived token, which OIDA does not issue. The static "auth" object needs a pre-registered client, which OIDA does not hand out self-service.
{
"mcpServers": {
"oida": { "url": "https://mcp.projectoida.com/mcp/<your-workspace>" }
}
}Codex (CLI and IDE extension) Tested
- Run the commands below. "codex mcp login oida" opens the browser for the OIDA sign-in and consent page. "codex mcp list" then shows the server as authenticated.
- The same entry lands in ~/.codex/config.toml under [mcp_servers.oida] (url = "https://mcp.projectoida.com/mcp/<your-workspace>"). Add default_tools_approval_mode = "writes" so write and governance tools ask for approval. The file is shared with the ChatGPT desktop app.
- IDE extension: gear → MCP servers → Add server → Streamable HTTP → paste the endpoint → save → Authenticate → Restart extension.
- Limits: Codex in ChatGPT web/cloud does not read local configuration and cannot connect. bearer_token_env_var and http_headers need a long-lived token, which OIDA does not issue. If login fails on the redirect URI, pin mcp_oauth_callback_port and retry (loopback port handling is not yet verified).
codex mcp add oida --url https://mcp.projectoida.com/mcp/<your-workspace>
codex mcp login oidaGitHub Copilot in VS Code Documented
- VS Code 1.99 or later. Add the server below to .vscode/mcp.json (or run "MCP: Open User Configuration"). Alternatively run code --add-mcp with the same JSON.
- Start the server from the MCP view. VS Code performs dynamic client registration with the OIDA authorization server and opens the browser for the OIDA sign-in and consent page. Approve, then trust the server when asked.
- Copilot Business and Enterprise: an administrator must enable the "MCP servers in Copilot" policy first. Tools without a read-only hint show a confirmation dialog.
- Not supported: the Copilot coding agent, cloud agent, code review and the JetBrains, Xcode and Eclipse plugins only accept a static bearer header, and OIDA issues no long-lived tokens. Visual Studio 17.14+ works through its Auth CodeLens.
{
"servers": {
"oida": { "type": "http", "url": "https://mcp.projectoida.com/mcp/<your-workspace>" }
}
}Any MCP client (Streamable HTTP + OAuth 2.1) Tested
- Use the Streamable HTTP transport with the workspace endpoint URL: JSON-RPC over POST with Accept: application/json, text/event-stream. The endpoint is stateless (no session id. GET and DELETE answer 405).
- Discovery: an unauthenticated POST returns 401 with WWW-Authenticate: Bearer resource_metadata="…/.well-known/oauth-protected-resource/mcp/<slug>". That document names the authorization server (Supabase Auth, issuer https://crfewyiflgsadexrskdt.supabase.co/auth/v1) and its RFC 8414 / OpenID metadata.
- Register dynamically at the registration_endpoint with token_endpoint_auth_method "none" and your exact redirect URI (https, or http on localhost), then run the authorization-code flow with PKCE S256 and resource=https://mcp.projectoida.com/mcp/<your-workspace>. The user signs in to OIDA and approves the consent page.
- Send Authorization: Bearer <access_token> on every request and refresh with the rotating refresh token. Tokens must carry the OAuth client_id claim: OIDA web-session tokens are refused, and no long-lived tokens exist.
curl -si -X POST https://mcp.projectoida.com/mcp/<your-workspace> \
-H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"curl","version":"0"}}}'