Skip to main content
Use your API’s MCP URL, such as https://vitalog-api.example.com/mcp. The UI address is where you sign in and review records; it is not the MCP endpoint. Open Account Settings → MCP Guide in Vitalog to copy configurations for your installation. The examples below use the example API hostname. Replace it when self-hosting.

Connect with OAuth

Add the MCP URL to a client that supports Streamable HTTP and MCP authorization. The client discovers the authorization server, registers or supplies its client metadata, and opens Vitalog’s consent page. Sign in with the root email and password, review the requesting client’s identity, callback destination and requested access, then approve. The client receives its token through the OAuth callback and token exchange. You do not need to create or paste an API key. Tokens expire after 30 days; reconnect after expiry. Revoke a connection from Account Settings → MCP Connections after verifying your root credentials.
Add this to ~/.codex/config.toml:
Run codex mcp login vitalog to sign in.
Other clients can use the same URL and OAuth discovery. Vitalog follows the MCP authorization specification independently of the client’s brand. See the OAuth contract for registration, PKCE, scopes and callback requirements.

Connect with an API key

Create a 30-day key in Account Settings → API Keys or at /api-keys on the UI. Store it privately in your client and send Authorization: Bearer <your-key> with every MCP request, including initialization and discovery. Do not put the key in the URL. For example, a client accepting custom headers can use this structure:
Prefer your client’s secret storage or environment-variable support when available. Manually generated API keys enforce their selected read-only, edit or administrative permissions and expiry. Read-only keys discover and call read tools; edit and administrative keys also write records and goals. Key management remains outside MCP. OAuth connections use the requested health:read and/or health:write scopes. Browser dashboard sessions cannot authenticate MCP.

Tool discovery and calls

Vitalog uses stateless Streamable HTTP with JSON responses. For raw MCP POST requests, send Accept: application/json, text/event-stream. The official SDK negotiates the protocol version. Clients initialize, list tools and call the MCP tools; logging, discovery, reading, correction and goals share the REST domain service.

Troubleshooting

Check your client’s current documentation for client-specific connection controls: Codex, Claude Code, Cursor and VS Code.