Skip to main content

ironclaw mcp

Manage MCP (Model Context Protocol) servers. MCP servers are hosted services that provide tools and capabilities to IronClaw through a standardized protocol.

Subcommands

  • add - Add an MCP server
  • remove - Remove an MCP server
  • list - List configured MCP servers
  • auth - Authenticate with an MCP server (OAuth flow)
  • test - Test connection to an MCP server
  • toggle - Enable or disable an MCP server

ironclaw mcp add

Add a new MCP server to your configuration.

Syntax

Arguments

<NAME> Server name (e.g., notion, github, slack). <URL> Server URL (e.g., https://mcp.notion.com).

Flags

--client-id <ID> OAuth client ID (if authentication is required). --auth-url <URL> OAuth authorization URL (optional, can be discovered). --token-url <URL> OAuth token URL (optional, can be discovered). --scopes <SCOPES> Comma-separated list of OAuth scopes to request. --description <TEXT> Server description.

Examples

Add Server Without Authentication

Add Server With OAuth

Add Server With Full OAuth Configuration

Output


ironclaw mcp remove

Remove an MCP server from your configuration.

Syntax

Arguments

<NAME> Name of the server to remove.

Examples

Output


ironclaw mcp list

List all configured MCP servers.

Syntax

Flags

--verbose, -v Show detailed information.

Examples

Output

Default output:
Symbols:
  • ● - Enabled server
  • ○ - Disabled server
Verbose output:

ironclaw mcp auth

Authenticate with an MCP server using OAuth.

Syntax

Arguments

<NAME> Name of the server to authenticate with.

Flags

--user, -u <USER_ID> User ID for storing the token.
  • Default: default

Examples

Interactive Flow

The command initiates an OAuth flow:

Dynamic Client Registration (DCR)

If the server supports DCR and no client ID is configured, the command will:
  1. Discover the server’s OAuth endpoints
  2. Dynamically register a client
  3. Use the registered client for authentication

Re-authentication

If already authenticated, you’ll be prompted:

ironclaw mcp test

Test connection to an MCP server and list available tools.

Syntax

Arguments

<NAME> Name of the server to test.

Flags

--user, -u <USER_ID> User ID for authentication.
  • Default: default

Examples

Output

Successful connection:
Connection failure:
Not authenticated:

ironclaw mcp toggle

Enable or disable an MCP server.

Syntax

Arguments

<NAME> Name of the server to toggle.

Flags

--enable Enable the server. --disable Disable the server. If neither flag is provided, the state is toggled.

Examples

Output

or

MCP Server Configuration Storage

MCP server configurations are stored in:
  1. Database (if available) - mcp_servers table for user default
  2. Disk fallback - ~/.ironclaw/mcp_servers.json

Configuration File Format

~/.ironclaw/mcp_servers.json:

OAuth Token Storage

Access tokens are stored securely:
  • Encrypted with SECRETS_MASTER_KEY
  • Stored in the secrets table
  • Named as mcp_<server_name>_access_token
  • Refresh tokens stored as mcp_<server_name>_refresh_token

Common MCP Servers

Notion

GitHub

Slack

Troubleshooting

”Server not found”

Check configured servers:
Add the server if missing:

“SECRETS_MASTER_KEY not set”

Run onboarding to generate a master key:
Or set it manually in .env:

“Authentication failed (token may be expired)”

Re-authenticate:

“OAuth client_id not configured”

Add the server with a client ID:

“Server does not support OAuth authentication”

The server may:
  • Not support OAuth
  • Support a different authentication method
  • Require Dynamic Client Registration (DCR) - happens automatically if supported
  • tool - Manage WASM tools (alternative to MCP)
  • onboard - Initial setup including secrets key
  • doctor - Verify configuration