Skip to main content
API MCP sends requests with your Straddle API key. The key’s permissions determine which Straddle operations the server can execute; your client controls when it asks you to approve a tool request.

Supply the API key

Set STRADDLE_API_KEY in the environment that starts your client, or use the Straddle plugin’s credential field in Cursor. Direct client configuration stores a reference to the variable. See Connect MCP for the exact syntax. Use a key from the Straddle dashboard. API MCP uses that key as a bearer token and needs no Scalar login. Keep the key in the client environment or credential field, outside prompts, source files, and reports. A key saved in the Straddle CLI configures the CLI. Configure the MCP client’s credential separately.

Match the environment

Choose the host explicitly in each API request: Use a key for the same environment. Confirm the key’s environment in the dashboard and the host in the request.

Review API execution

The API MCP’s execute-request can perform reads, creates, updates, deletes, and sensitive-data operations permitted by the key. A production key can authorize production writes. Keep tool approval prompts enabled. Before approving execution, inspect the method, host, path, account header, and request body. For a write, check the intended effect and the idempotency key as well.

Understand the skill rules

The Straddle skills add instructions for integration work. These are workflow rules followed by the agent, separate from the server’s API permissions: The agent follows these routing instructions. The server still accepts any operation permitted by the supplied key.

Interpret verification

Documentation search and specification discovery can succeed without an authenticated Straddle request. Verify API access with a permitted read against the environment and account you intended. A successful read proves access to that operation and account. Follow Read an account through API MCP for a focused check.