Skip to main content
AI client guides

Connect Claude Code to StackJack

Claude Code is Anthropic's CLI coding agent. It connects to StackJack as a remote MCP server (MCP is the Model Context Protocol, the open standard AI tools use to call external tools), registers…

Written By Christopher Scaminaci

Last updated 6 days ago

Claude Code is Anthropic's CLI coding agent. It connects to StackJack as a remote MCP server (MCP is the Model Context Protocol, the open standard AI tools use to call external tools), registers itself automatically, and signs you in through your browser — no headers to manage.

Prerequisites

  • Claude Code installed and reasonably current (the claude mcp login command exists in v2.1.186 and later; older builds still support /mcp for sign-in).
  • A StackJack account that is a member of your workspace. Any team member can connect — no admin-created credentials needed for the sign-in path.
  • Your StackJack MCP endpoint URL. Copy it from the MCP Setup page in the portal — that card shows the address for your workspace's region. The examples in this guide use the US address, https://mcp.stackjack.io/mcp; other regions have their own hostname. See Your region and your endpoint.
  1. Add the server with just the URL:

    claude mcp add --transport http stackjack https://mcp.stackjack.io/mcp --scope user
    
  2. Sign in — either run /mcp inside a Claude Code session and pick StackJack, or run:

    claude mcp login stackjack
    
  3. A browser opens to the StackJack sign-in page. Use the same email, password, and MFA you use for the StackJack Portal. Your tools are then available in every Claude Code session.

Claude Code connects with just a URL, and like other Claude clients it may identify itself to StackJack as a shared app (CIMD) rather than a private per-install registration. If it does, after the browser sign-in StackJack shows a "Authorize Claude Code" consent screen with a "Verify before you approve" panel. Because Claude Code runs locally, your authorization is delivered to localhost, and the screen flags this with a local application notice — that is expected; continue only if you started the sign-in yourself. Choose Allow access to finish. A shared-app authorization then appears as a Connected apps entry an admin can revoke per member on the Team page (a per-install connection appears as a read-only AI session instead — in your own MCP Setup self-view, and per member on Team for admins). See How AI tools authenticate for the full walkthrough.

Scope choices

ScopeWhere it's storedUse it when
--scope user~/.claude.jsonYou want StackJack available across all your projects (recommended)
--scope project.mcp.json in the repoYou want to commit the server entry so teammates get it too. URL only — never a credential. Each teammate signs in with their own StackJack account

Manual credentials (headless / CI fallback)

For non-interactive environments that can't open a browser, an owner, co-owner, or Administrator first creates an MCP client in the portal (see Managing MCP credentials). Base64-encode CLIENT_ID:CLIENT_SECRET and pass it as a header:

claude mcp add --transport http stackjack https://mcp.stackjack.io/mcp \
  --header "Authorization: Basic <BASE64_ENCODED_CREDENTIALS>"

Or write it into ~/.claude.json (user scope), which stays on your own machine:

{
  "mcpServers": {
    "stackjack": {
      "type": "http",
      "url": "https://mcp.stackjack.io/mcp",
      "headers": {
        "Authorization": "Basic <BASE64_OF_CLIENT_ID:CLIENT_SECRET>"
      }
    }
  }
}

Never put a credential in the project's .mcp.json. That file is the shareable scope — its whole purpose is to be committed so teammates pick the server up, which means a credential written there is committed to the repository and shared with everyone who clones it. Keep the two apart:

FileWhat belongs in it
.mcp.json (project scope, committed)The URL only. Teammates then sign in individually.
~/.claude.json (user scope, your machine)A credential, if you must use one.
CI secret storeThe credential for an automated environment. Supply it to the --header argument from the secret, never as literal text in a workflow file.

Two more things about the encoded value. Base64 is encoding, not encryption — anyone who reads the string can decode it back to the client id and secret, so treat it as the secret itself. And a command you type puts it in your shell history, so prefer a method that reads it from a secret store.

A static header disables sign-in. With one configured, a wrong, rotated, or revoked credential makes Claude Code report the server as failed, and there is no sign-in fallback to recover through. Prefer the sign-in path unless you are in CI.

Tool limits

Claude Code does not publish a hard MCP tool cap, but every tool description consumes context. Depending on your connectors and plan, StackJack can expose hundreds of tools; if that's more than your workflow needs, connect through a restricted client or ask your admin to trim your grants — see Choosing tools for each client.

Troubleshooting

  • Server shows "failed" — if you configured a static Authorization header, the credential is wrong, rotated, or revoked. Fix the header or remove it and use sign-in instead.
  • Sign-in says no account was found — sign up in the portal first, or ask your team admin for an invite.
  • For anything else, see Connection troubleshooting.