---
title: "Connect an agent"
description: "Point any MCP client at one address. There is nothing to install."
---

Contextaco speaks [MCP](https://modelcontextprotocol.io) and nothing else. There is no SDK, no library, and nothing to install — you give a client one address and it gains a small set of tools.

> **Note**
>
> The address is the **bare host**, with no path after it:
>
> ```
> https://mcp.contextaco.dev
> ```
>
> It is also the OAuth resource identifier your client binds its token to, so it must be used exactly as written. Adding a path produces a 404.

## No credential at all

Add the address above as a **custom connector** in any client that supports remote MCP servers.

The server answers the first call with a challenge, your client registers itself automatically, and you are sent through a sign-in. You approve the connection once. **There is no key to copy anywhere** — if a setup guide tells you to paste a secret, it is out of date.

> **Warning**
>
> **A connected agent acts as you.** It can read your tacos — including private ones — write and delete entities, attach files, fork, and change a taco's visibility, which includes making a private taco public.
>
> Sign-in happens in your browser and your client keeps the credential. To cut an agent off, remove the connector in that client.

> **Note**
>
> **API keys were removed.** Contextaco used to offer a `taco_sk_…` bearer token as a fallback for headless setups. That credential never expired, could not be scoped, and had to be copied out of a web page into a shell — so it is gone, and the browser sign-in above is the only way in.
>
> This means **CI and headless machines are not supported**: every flow our authorization server offers needs a browser. An agent connecting to Contextaco has a person attached to it.

## If you use Claude Code

There is a plugin, and it is the shortest path — it adds the connector for you and brings one extra thing with it.

```
/plugin marketplace add contextaco/plugin
/plugin install contextaco@contextaco
```

Sign-in works exactly as above: the plugin carries the address, not a credential.

> **Note**
>
> The plugin is a convenience, not a requirement. Everything it configures, you can do by adding the address as a custom connector — and every other client does it that way.

## Confirming it worked

Ask your agent to show you your own account. It should come back with your handle and the tacos you own. If it returns nothing at all, or asks you to sign in again, see [Troubleshooting](/troubleshooting).

## Make capture automatic

Your agent is told what Contextaco is for when it connects. Putting the same instruction in your own project file makes it far more reliable — an agent follows the conventions you give it closely, and they sit alongside the rest of your project's rules.

Add this to your project's `CLAUDE.md`, or whichever instructions file your agent reads:

```markdown
## Contextaco

Capture durable context as work happens, without being asked. When a decision is made after weighing real alternatives, a constraint turns up that is written down nowhere, an approach is tried and abandoned for a reason, or a conclusion costs real effort to reach — write it to Contextaco, under the taco for this line of work, creating one if there is not one yet.

Ask first: would someone continuing this work be meaningfully worse off without it? If not, skip it. Most conversations are not worth recording, and recording them makes the ones that matter harder to find.

When I say "taco it" — or taco this, or make a taco of it — I mean Contextaco specifically, and I have already decided it is worth keeping: write it rather than weighing whether to.

Before starting something unfamiliar, check Contextaco for prior work on it.
```

The second paragraph is the important half. Without it an agent tends to record everything, which spends your storage and buries the work you actually wanted to keep.

## Choosing your handle

Your handle is the first half of every address you publish — `handle/taco-handle` — and it is chosen **once**, on the web. No agent can set it or change it, deliberately: it is permanent, and only the person gets to settle something permanent.

Your display name and bio are separate, changeable, and public. An agent can update those.
