Logo StartupKit
EN

Connecting AI Assistants

Connect Claude, Claude Code, Codex CLI, OpenCode, or any other MCP client to manage your hiring workflows with AI.

Why It Matters

MCP (Model Context Protocol) lets AI assistants like Claude interact directly with your Kit account: listing job postings, reviewing templates, inviting team members, and more. Instead of copy-pasting between your browser and an AI chat window, the assistant reads and acts on your real data.

What You Need

  • A Kit account. Any member can connect; admin access is not required
  • An MCP client: Claude (web, desktop, or mobile), Claude Code, Codex CLI, OpenCode, or any MCP-compatible app

Connecting is a personal act: the connection belongs to you, not to the account. What the assistant can reach follows your role (your per-module access levels, re-read on every call), so two people connecting the same client to the same account get different toolsets.

Setup

Let your agent set itself up

Paste this one line into Claude Code, Codex CLI, Cursor, or any other agent:

Fetch and execute the appropriate instructions to set me up for Kit from https://startupkit.app/agent-setup/prompt.md

The agent fetches Kit’s published setup document, registers both MCP servers, and tells you when to approve the connection in your browser. The Onboard your agent button in the header of any docs page copies the same line.

Two servers get registered. kit reaches your account and needs your approval; kit-docs is public, needs no account at all, and answers documentation, pricing, and hiring-template questions from the first call.

Set it up by hand

The rest of this page is the manual path, and the reference for what that prompt does.

Navigate to Integrations > MCP Setup. You’ll see your MCP Server URL and ready-to-copy configuration for each client.

Claude (web, desktop and mobile)

Claude connects to Kit as a custom connector. Add it once on claude.ai or in Claude Desktop, and it is also available in the Claude apps for iOS and Android.

  1. In Claude, open Customize > Connectors.
  2. Click +, then Add custom connector.
  3. Enter the name Kit and the URL https://startupkit.app/api/v1/mcp. Leave the OAuth client ID and secret blank: Claude registers itself with Kit automatically.
  4. Click Add, then Connect. Kit’s consent screen opens in your browser: pick the account and the modules to grant, as described in The Consent Screen.
  5. In a chat, open the + menu and choose Connectors to switch Kit on or off for that conversation.

On Claude Team and Enterprise plans, only an Owner can add a custom connector. The Owner adds Kit once under Organization settings > Connectors (Add, then Custom, then Web, with the same URL). Each member then finds it under Customize > Connectors and clicks Connect to sign in with their own Kit account, so every member gets only what their own Kit role allows. On the Free plan, Claude allows one custom connector.

If Kit appears in Claude’s connector directory, you can add it from there instead of pasting the URL. The consent screen and the scopes are the same either way.

Try these once Kit is connected:

  • “Which job postings are open, and how many applications does each have?” (hiring_list_job_postings)
  • “Which hiring reviews are waiting for my decision?” (hiring_list_pending_decisions)
  • “What’s in my CSiRT queue right now, critical first?” (csirt_list_my_queue)

Each prompt needs its module granted on the consent screen: Hiring for the first two, CSiRT for the third.

Claude Code (CLI)

Run this in your terminal:

claude mcp add --scope user --transport http kit https://startupkit.app/api/v1/mcp

Or add to your .mcp.json config file:

{
  "mcpServers": {
    "kit": {
      "type": "http",
      "url": "https://startupkit.app/api/v1/mcp"
    }
  }
}

Codex CLI

Run this in your terminal:

codex mcp add kit --url https://startupkit.app/api/v1/mcp

codex mcp add also opens your browser for the consent screen. In codex mcp list, the Auth column shows OAuth once you’re signed in; if it shows Not logged in, run codex mcp login kit. Codex speaks Streamable HTTP directly, so no mcp-remote proxy is involved. Restart any open Codex session to load the new server.

Equivalent entry in ~/.codex/config.toml:

[mcp_servers.kit]
url = "https://startupkit.app/api/v1/mcp"

After editing the file by hand, still run codex mcp login kit once to obtain a token. Check the connection with codex mcp list; drop the credential with codex mcp logout kit.

OpenCode

Add the server to opencode.json, either the global one at ~/.config/opencode/opencode.json or a per-project file in your repo root:

{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "kit": {
      "type": "remote",
      "url": "https://startupkit.app/api/v1/mcp",
      "enabled": true,
      "oauth": {}
    }
  }
}

Then authorize:

opencode mcp auth kit

opencode mcp list shows each server’s authentication status, and opencode mcp logout kit removes the stored token. "oauth": {} states that this server authenticates through OAuth; "oauth": false is the opt-out used for servers that take a static API key in headers instead. Kit does not.

Clients that only run local servers

Claude Desktop no longer needs this: use the custom connector above. An MCP client that can only launch local servers can still reach Kit through the mcp-remote proxy, which runs the OAuth flow on your machine:

{
  "mcpServers": {
    "kit": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://startupkit.app/api/v1/mcp"]
    }
  }
}

Authorization Flow

When your MCP client connects for the first time:

  1. Your browser opens an authorization page on Kit
  2. If you belong to multiple accounts, you select which one to connect
  3. You choose which modules the assistant can access, and whether each is read-only or read & write
  4. Kit issues a token scoped to that account and those modules
  5. The client stores the token and refreshes it automatically

Tokens expire after 2 hours and are auto-refreshed. You don’t need to re-authorize unless you revoke access, or the connection goes 90 days without being used. See Automatic Disconnection below.

Scopes

MCP access is granted per module. Each module has a read scope and a write scope:

Module Read Scope Write Scope What It Covers
Hiring hiring_read hiring_write Job postings, applications, reviews, talent pool, templates, and Career Portal tools
CSiRT csirt_read csirt_write Vulnerability reports, triage, researcher messages, bounties, program setup
Outreach outreach_read outreach_write Campaigns, prospects, email drafts, metrics
Compensation Research compensation_read compensation_write Salary benchmarks, market trends, role and location comparisons, and your tracked roles and regions (tracking also needs Hiring)
Training training_read training_write Training programs, slides, quizzes, attestations, completion status, and participant invitations
Performance performance_read performance_write Review cycles, participants, your own reviews, and the SOC 2 evaluation register
Team team_read team_write Members and invitations

The base mcp scope is always granted. It covers the global tools only: docs search, pricing plans, whoami, the PDF sanitizer, IP investigation, and the email checker.

When you authorize a connection, the consent screen walks you through:

  1. Pick the account: if you belong to multiple accounts, choose which one to connect
  2. Choose module access: each module appears as a row with a Read | Read & write segment. Writes are off by default; switch a module to Read & write only if the assistant should take actions rather than only look. Modules with risky write tools show a warning line explaining what you’re enabling.

Modules your account doesn’t have are hidden from the consent screen. Modules the account has but you don’t are shown dimmed and marked not part of your role: you can see they exist, but you can’t grant them. Kit drops them server-side even if they’re submitted anyway, so a connection can never hold a scope its owner has no access to. To gain one, ask an admin for that module; the row links to the request. Read & write for Team and Compensation Research can only be granted by account admins.

Tools from modules you didn’t grant never appear in the assistant’s tool list.

Connections authorized before module scopes existed have been disconnected. Reconnect through the consent screen and pick the modules you want to grant.

To change what a connection can do, revoke it on the MCP Setup page and connect again. The new consent replaces the previous grant.

Managing Connected Clients

The MCP Setup page shows all connected clients with:

  • App name: The MCP client that connected
  • Scopes: Per-module access granted, shown as chips (R for read, RW for read & write)
  • Authorized at: When the connection was made
  • Last used: When the client last called a tool

Click Revoke to disconnect a client. The client will need to re-authorize to connect again.

Every user can also review their own connections, across all accounts they belong to, at Account Settings → Connected clients. Admin access isn’t required; you always control the clients you personally authorized.

Automatic Disconnection

A connection that goes 90 days without being used is disconnected automatically by a nightly sweep. This is a hygiene measure for forgotten credentials: a token left on a laptop you stopped using shouldn’t stay valid forever.

What counts as use:

  • Any API call from the client resets the clock.
  • A token refresh counts too. A client that stays connected refreshes roughly every two hours, so it never goes dormant, no matter how long it sits idle between actual requests.
  • Activity is measured across the whole connection, not per token, so refreshes and calls both keep it alive.

What you’ll see:

  • Once a connection is within 30 days of lapsing, both settings pages show a warning next to it: “Disconnects on October 12, 2026 unless used”.
  • When it’s disconnected, Kit emails you (“Claude Code was disconnected from Kit”), naming the client, the account, and when it was last used. This email is always sent; it’s the only signal a credential stopped working.

To reconnect, run the authorization flow again from your MCP client and approve access. The disconnection removes a credential, never data.

Note

The 90-day window follows RFC 9700 §4.14.2 (OAuth 2.0 Security Best Current Practice): “Refresh tokens SHOULD expire if the client has been inactive for some time.” It matches Atlassian and Microsoft Entra; Google uses 6 months and GitHub 1 year.

Refused Is Not Disconnected

If your account requires passkeys and you hold none, your connection isn’t disconnected; it’s refused. Kit turns each call away while the answer stays no, because a token cannot present a passkey; the grant itself is untouched.

Refused (no passkey) Disconnected (90 days idle, or revoked)
The grant Survives, still listed on your MCP Setup page Removed
To fix it Add a passkey at Account Settings → Passkeys Run the authorization flow again
Re-authorization Not needed; calls resume on the next request Required

Nothing is revoked and nothing is lost either way. See Passkeys for what to enroll.

Quick Checklist

  • Navigate to Integrations > MCP Setup
  • Copy the config for your MCP client
  • Run or paste it into your client’s configuration
  • Authorize the connection when your browser opens: pick the account and choose module access (Read or Read & write) on the consent screen
  • Test with “What job postings do I have?” in your AI assistant
  • Verify the connection appears in Connected Clients

For the separate account-level controls behind Kit’s built-in AI (provider keys, preferred provider, spend caps, and usage), see AI Providers & Spend Controls.

Type to search...