Step 1: Create an API Key
The client authenticates to Earnie with an API key, sent with every request as anAuthorization: Bearer <key> header.
- In Earnie, go to Settings → API keys and select Generate key.
- Name the key after the agent that will use it, for example
claude-code-alex. - Under What this key will hold, choose the Coding agent (MCP) preset.
- Leave Allow agents to triage findings off unless you want the agent to record triage decisions. See Letting an Agent Triage.
- Choose the projects the key can reach, and its expiry.
- Generate the key, and copy it straight away. It’s shown only once.
A tool whose permission the key lacks is hidden from the agent entirely. Using Earnie Through MCP describes each tool.
Step 2: Find Your MCP Address
Earnie’s MCP server is part of your Earnie deployment, at your Earnie address followed by/mcp/v1. For example, if you open Earnie at https://acme.earnie.example, the MCP address is:
Step 3: Add Earnie to Your Client
There are two ways to connect. Choose one:Option A: Set Up with the Earnie CLI
This is the recommended route for a repository, because it also writes your project’s policies into the agent’s instructions file and installs review hooks.- Install the Earnie CLI.
-
Sign in with the key you created:
-
From inside your repository, run setup:
--project, EARNIE_PROJECT, or the repository’s Git remote, and asks you to pick one if none of those identifies it.
It then writes:
- The connection — the MCP address and your key, in each client’s user-level configuration, under a server named
earnie. - The managed policy block — your project’s policies as plain rules, in
CLAUDE.md,.cursor/rules/earnie.mdc,.github/copilot-instructions.md, orAGENTS.md. - Review hooks — for Claude Code, Cursor, and Codex.
Codex needs one more step. Codex doesn’t run project hooks until you
approve them. Inside Codex, run
/hooks and trust Earnie’s hook
definitions.Option B: Use an Install Snippet from Earnie
When you generate a key with the Coding agent (MCP) preset, the panel that shows the key also shows Connect your coding agent, with an install snippet for each client. The snippets are built with your own MCP address, and they’re shown only once, with the key. Some snippets carry the key itself. Others leave it out, so the key doesn’t end up in your browser history. Follow the instructions for your client:Claude Code
Run the command in the repository you want the agent to work in. It includes your key:Cursor
Open the link from the panel. Cursor offers to install the server, already configured. The link doesn’t contain your key, so set it as an environment variable namedEARNIE_API_KEY before you start Cursor. The installed configuration reads it as Bearer ${env:EARNIE_API_KEY}.
VS Code
Open the link from the panel. VS Code offers to install the server in your user profile, and asks for your key as a password when you install it. The link itself doesn’t contain the key.Codex
Add this block to~/.codex/config.toml. It includes your key:
Setting a Default Project
If the key can reach more than one project, the panel offers Default project for this client. Choosing one adds anX-Earnie-Project header to the snippet, set to that project’s ID:
Claude.ai and ChatGPT
Claude.ai and ChatGPT connect from the vendor’s own cloud rather than your machine. That means:- they need an Earnie deployment that’s reachable from the public internet, so an on-premise Earnie can’t be used with them
- they expect OAuth, which Earnie doesn’t offer yet, so an API key alone isn’t enough
Authorization and the value Bearer <key>, including the space after Bearer. A Claude connector’s authentication can’t be edited afterwards, so rotating the key means removing the connector and adding it again.
For a developer working in a repository, the four clients above are the supported route.
Step 4: Check the Connection
- Restart your client, so it loads the new configuration.
-
Ask the agent to ping Earnie, for example:
Use the Earnie health ping tool to check the connection.
The agent callsplatform_health_ping, which works with any valid key. A working connection returns the server’sstatus, the currenttimestamp, and the server’s name and version. -
Ask a real question, for example:
Which Earnie projects can you see?
The agent callsearnie_list_projectsand lists the projects your key can reach, with a link to each project’s Dashboard.
For Administrators: Deployment Settings
The MCP server is always available on every Earnie deployment. There’s no setting to turn it on. These environment variables, set on the Earnie deployment, change how it behaves:
Without
EARNIE_MCP_REVIEW_BUDGET_SECONDS, the wait comes from Settings → Scan Configuration, on the Self-check tab, under Self-check wait budget. Its default is 45 seconds.