Connect AI Agents to Kit: Claude Code, Codex and More

Connect Claude Code, Codex, Grok Bot, Grok Build, Hermes, pi and OpenClaw to Kit with MCP and OAuth. Compare setup paths and try a scoped first task.

Ernest Bursa

Ernest Bursa

Founder · · 13 min read
Founder reviewing a handwritten hiring and security briefing beside a closed laptop

AI agent harnesses such as Claude Code, OpenAI Codex, Cursor, Gemini CLI, OpenCode, Grok Build, Grok Bot, Hermes, pi and OpenClaw can use MCP to connect to tools outside their own workspace. To reach your Kit account, the client needs remote MCP and browser OAuth. Choose one account and start with one module’s read access.

A useful first task identifies work you can finish: a review waiting for your decision, a security report needing attention, or a training participant who finished the course but has not signed. Ask for the record, the reason it needs attention and the next human action.

What should your agent do first?

Start with a question whose answer you can check in Kit. Give the agent a narrow scope, a small output limit and a clear stopping point.

A founder might ask:

Check my Kit identity and account. List open job postings and pending hiring decisions. Return at most five items with record IDs and available Kit links. Do not change records or draft messages. If a result is partial, say so.

The result should be a short list of work to inspect. It should not invent a candidate ranking, merge different applications for the same person, or report that a queue is empty when it only read the first page.

For a security owner, the equivalent is a list of attention signals, critical first, with counts and example reports. For an outreach operator, it is a list of pending drafts to review. Both use tools Kit already exposes, within your existing hiring or security process.

Your task What the agent can prepare What you check
Unblock hiring Overdue obligations by responsible teammate, using hiring_get_team_bottlenecks Requires Hiring Insights access; shared or fallback ownership is not proof of blame
Start security triage Attention signals, counts and example reports from csirt_list_my_queue Queue scope, report evidence and ownership; examples are not the full report list
Follow up with one candidate A pending reply draft Recipient, latest thread and exact wording
Inspect uncertain outreach delivery Messages needing an operator decision from outreach_list_delivery_reviews Inspect the evidence before any retry; an unknown delivery outcome is not a failed send
Follow up on training Completion blockers from training_get_completion_status Requires Training admin access; distinguish unfinished content from an unsigned attestation
Prepare your performance review Your assignments, questions and due dates from performance_list_my_reviews The person supplies the evaluation; the agent must not invent performance evidence or submit it
Check an advertised salary range A filtered benchmark after compensation_get_filter_options Check coverage, geography, freshness, currency and employment type; advertised pay is not actual pay

The MCP tools reference describes the available tools. Your grant determines which module tools are listed; your current Kit role also limits the records and actions you can use.

A personal queue is not the whole team’s backlog. Hiring pending decisions are those you may decide; the security queue defaults to work assigned to you. Ask for the scope and any remaining pages before treating a briefing as complete.

A useful hiring result names the waiting application, elapsed time and responsible role. Ask for at most five actionable rows and explain what remains outside the summary.

Use the client you already work in: a coding harness beside the repository, an editor assistant beside the project, or a private personal-agent session for a recurring digest. Those are workflow choices, not measured accuracy differences.

Which AI agent harnesses work with Kit?

Claude Code, Codex, Cursor, Gemini CLI, OpenCode, GitHub Copilot, Kilo Code, Goose, Hermes, pi and current OpenClaw document remote MCP with OAuth. That gives each a connection route to try with Kit. We checked first-party instructions and Kit’s implementation on October 5, 2026; we have not completed authenticated Kit tests in every client.

An agent harness is the application that runs the model, exposes tools and controls execution. An editor integration, terminal agent and personal gateway can use the same Kit endpoint while handling approval, memory and scheduling differently. Claude and ChatGPT connector apps are separate interfaces; agent SDKs require you to build and operate the client yourself.

This comparison covers common coding and personal-agent setups. It is not a market-share ranking.

Harness or client Documented connection Setup detail that matters
Claude Code Native HTTP MCP and browser OAuth Register Kit, then authenticate through claude mcp login kit or /mcp; Claude chat connectors have a separate setup
OpenAI Codex Native Streamable HTTP and OAuth CLI and desktop/IDE surfaces share MCP configuration; use codex mcp login kit for Kit authorization
Cursor Native Streamable HTTP and OAuth Configure the server in Cursor’s MCP settings; a project configuration and a personal configuration have different reach
Google Antigravity Remote Streamable HTTP and OAuth discovery Use the installed product’s MCP settings; its configuration differs from Gemini CLI
Zed Remote URL configuration and standard MCP OAuth Connect through Zed Agent; external agents using ACP have their own tool-forwarding behavior
Gemini CLI Native HTTP MCP and OAuth discovery Use /mcp auth kit; its local callback and issuer checks must succeed
OpenCode Native remote MCP and OAuth Stable configuration uses mcp.kit with type: remote; authenticate with opencode mcp auth kit
GitHub Copilot in VS Code and Copilot CLI Both document remote HTTP and OAuth VS Code’s MCP: Add Server and the CLI’s /mcp flow are separate; organization policy can restrict access
Kilo Code Native remote HTTP and OAuth Use the extension’s MCP settings or Kilo CLI’s mcp add and mcp auth commands
Goose Remote Streamable HTTP extension with OAuth Choose a remote extension; Kit advertises dynamic registration, not every OAuth option Goose supports
Grok Build Native remote HTTP MCP with browser OAuth Use grok mcp add --transport http; inspect imported and project configurations before adding Kit
Grok Bot Team Bots document custom Remote HTTPS MCP plugins with OAuth Each teammate signs in individually; personal Bots share a cloud computer and account-wide connectors
Hermes Native remote MCP and OAuth Log in from a fresh terminal, then reload the chat; visible-tool filters do not reduce the token’s grant
pi Native Streamable HTTP and OAuth from 0.99.0 The September 29 release added built-in MCP; updated pi does not need a community adapter
OpenClaw Native registry with Streamable HTTP and OAuth in v2026.9.8 Native credentials and mcporter credentials are separate; use a private gateway you control
Devin Local / Windsurf users Current Devin Local documents Streamable HTTP and OAuth Legacy Cascade/Windsurf MCP uses a different configuration; follow the guide for the installed product

Some clients need a qualification. Continue documents Streamable HTTP in Agent mode, but its OAuth route was not established in the inspected guide; verify authentication in the installed version. Kiro documents remote MCP and OAuth, but the inspected docs did not establish Streamable HTTP interoperability with Kit. Cline documents Streamable HTTP and its current core source implements browser OAuth; confirm that the installed surface exposes that sign-in flow. A static-header example is not a Kit account recipe. The Roo Code repository is archived and its README says the extension shut down on May 15, 2026; it is not a current recommendation.

Use the agent setup guide for client routes, account verification and a bounded first task. The main connecting guide also covers Claude connectors and manual configuration. A listed server proves registration; the account check proves which Kit account the connection reaches.

Can Grok Bot and Grok Build connect to Kit?

Grok Bot and Grok Build document remote MCP connections with OAuth. Both offer a setup route to try with Kit, but they are separate products: Build is a coding agent in your terminal; Bot works across apps on a persistent cloud computer. These routes have not been authenticated and tested against Kit.

For Grok Build, add Kit’s account endpoint:

grok mcp add --transport http kit https://startupkit.app/api/v1/mcp
grok

In the session, open /mcps, select Kit and press i if sign-in is pending. Complete Kit’s browser consent with one module’s read access. Press r to refresh after configuration changes; grok mcp doctor kit diagnoses connectivity. Check existing registrations first: Build can import Claude and Cursor configurations, and project entries can replace a user entry.

For Grok Bot, Team Bots document a custom Remote HTTPS MCP plugin route with the same account URL. The setup guide gives the Team Bot owner’s UI steps; a personal Bot’s custom-plugin interface may differ. Complete browser OAuth instead of supplying a REST API key. We have not verified a Kit Marketplace listing.

Personal Bots share files, browser sessions and command-line credentials, and their connectors are account-wide. Giving one personal Bot a different name or job does not isolate its access. Team Bots document per-person OAuth: each teammate signs in with their own account. Verify whoami in each person’s private chat before reading Kit records. A routine belongs to its creator; publishing a Team Bot does not create one shared schedule.

Start with the same bounded worklist as any other client. Keep candidate and vulnerability details out of shared Bot chats and team memory. Grok chat’s Business connectors and the xAI API’s remote MCP tools are separate surfaces; their setup is not the Bot or Build recipe.

Connect the account you intend to use

Kit’s account-data endpoint is https://startupkit.app/api/v1/mcp. It uses OAuth: your client opens a Kit authorization page, you sign in, choose the account and select module access. A regular Kit REST API key does not authorize this MCP endpoint.

The public endpoint, https://startupkit.app/mcp, serves documentation and catalog tools. It is useful for learning about Kit, but it cannot read your hiring pipeline. If your agent can search docs but cannot find your applications, check the endpoint before trying broader permissions.

There are also two different logins involved. Signing the agent into its model provider lets it generate answers. Authorizing Kit lets it call your account’s tools. One does not replace the other.

On the Kit consent screen, start with the module you need and leave its access at Read. Confirm the selected account after connecting. A successful login is not enough if it selected the wrong company.

Kit checks both the grant and your current permissions. A connected agent cannot gain a module you do not have through your role. Client-side filters add another constraint on what the model can reach, but the server’s scope and record checks are the authorization boundary. The connecting guide explains those choices and how to revoke a connection.

Read the effect of each write tool

Write access covers more than drafting. Some tools save a draft; others change a record or enable delivery. Check the tool’s effect before granting it to an unattended run.

For Hiring replies, hiring_send_message saves a pending draft and returns its Kit link. Open that draft, check the recipient and thread, then use Confirm & send in Kit. Telling the agent “yes, send it” in chat does not release that pending reply.

That boundary does not apply to every Hiring action. Rejecting an application can notify the candidate according to your rejection-email settings. A read-only briefing should not need rejection tools or Hiring write access.

Security messaging has its own rules. Drafting a response gives you something to review. External direct sending depends on the program’s agent-send setting. Do not assume that a tool called “send message” behaves the same across modules.

Outreach approval is consequential too. Kit previews the exact recipient, sender, subject, body and version, then uses a confirmation token tied to that preview. Approval can make the message eligible for sending. A confirmation token ties approval to content; it does not prove that a human read that content.

For a first reply task, use a specific application ID:

Read the latest thread for this application. Draft a reply addressing the candidate’s question. Return the pending-draft link. Do not reject, advance or send anything. If you cannot read the complete relevant thread, stop and explain what is missing.

Ask for the actual draft link so you can check the reply in its thread.

Add a scheduled briefing after the first run works

A recurring digest can help once you have checked its account, contents and destination interactively. Start with the same read-only task that already produced a correct result.

Specify the module, maximum number of items and fields to include. For example, a private hiring digest can report application IDs, stages and available links without copying full CVs or email threads into a chat channel. Do not request personal fields that the operator does not need for that decision.

Also define failure behavior. If authorization expires, a queue is truncated or the intended account cannot be confirmed, the run should report that limitation. It should not claim “nothing needs attention” or switch to another source of data.

A useful digest makes its limits visible:

  • Which account and module it read.
  • When it ran and how many items it inspected.
  • Whether more pages or incomplete records remain.
  • Which Kit links the operator should open.

Scheduling is a client capability, separate from Kit access. A recurring prompt cannot grant the agent additional permissions or guarantee that a run will finish. Before depending on it, test how your chosen client handles expired credentials and failed calls.

Choose where the data goes

Running an agent on your laptop does not by itself keep returned Kit data on that laptop. The agent may send tool results to its model provider, save them in transcripts or deliver them to a messaging channel.

Before connecting private records, check the configured model, retention settings and output destination. A local model changes one part of that path; it does not remove the need to check logs, backups and chat delivery.

Treat candidate messages, prospect pages and vulnerability reports as source material. They can contain instructions written by someone outside your team. Those instructions should not change the task, expand access or redirect private information.

For your first test, request IDs and available links in the final answer. That limits the summary, not necessarily the tool response: a queue tool may still return candidate names, employee details or other private fields to the client and its model. Inspect the tool’s schema and data handling before the first call. Add richer context only when a task needs it and you have chosen where it may be processed.

Try one task in Kit

Pick the client you already use. Connect one account, grant one module read access and request a small briefing. Open its links and compare the result with Kit before adding drafts or scheduling.

The AI agent setup guide gives you client setup paths, a copyable bounded task and troubleshooting steps. If the first briefing helps you resolve a waiting Hiring or Security item, build from that concrete task.

Related articles

Try Kit for 30 days.

Hiring, security reports, and training in one account, for teams where none of it is a full-time job. Free for 30 days, card required. Cancel before it ends and you pay nothing.

Get started free