Supply the API key
SetSTRADDLE_API_KEY in the environment that starts your client, or use the Straddle plugin’s credential field in Cursor. Direct client configuration stores a reference to the variable. See Connect MCP for the exact syntax.
Use a key from the Straddle dashboard. API MCP uses that key as a bearer token and needs no Scalar login. Keep the key in the client environment or credential field, outside prompts, source files, and reports.
A key saved in the Straddle CLI configures the CLI. Configure the MCP client’s credential separately.
Match the environment
Choose the host explicitly in each API request:
Use a key for the same environment. Confirm the key’s environment in the dashboard and the host in the request.
Review API execution
The API MCP’sexecute-request can perform reads, creates, updates, deletes, and sensitive-data operations permitted by the key. A production key can authorize production writes.
Keep tool approval prompts enabled. Before approving execution, inspect the method, host, path, account header, and request body. For a write, check the intended effect and the idempotency key as well.
Understand the skill rules
The Straddle skills add instructions for integration work. These are workflow rules followed by the agent, separate from the server’s API permissions:
The agent follows these routing instructions. The server still accepts any operation permitted by the supplied key.