Connect Cline to StackJack
Cline is a VS Code extension (with a companion CLI) that connects to remote MCP servers over Streamable HTTP (MCP is the Model Context Protocol, the open standard AI tools use to call external tools).…
Written By Christopher Scaminaci
Last updated 6 days ago
Cline is a VS Code extension (with a companion CLI) that connects to remote MCP servers over Streamable HTTP (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). StackJack's setup wizard places Cline in Paste a credential, so the generated-credential path is the first-run path below. Recent Cline builds also offer browser OAuth as a supported alternative.
Prerequisites
- The Cline extension installed in VS Code.
- An MCP client credential created by an owner, co-owner, or Administrator (see Managing MCP credentials).
- A recent Cline build if you want to use the browser-OAuth alternative.
- Your StackJack MCP endpoint URL. Copy it from the MCP Setup page in the portal — that card shows the address for your workspace's region. The examples in this guide use the US address,
https://mcp.stackjack.io/mcp; other regions have their own hostname. See Your region and your endpoint.
StackJack setup-wizard path: generated credential
Before you paste a credential anywhere, three things about it.
- Base64 is encoding, not encryption. Anyone who can read the encoded string can decode it back to the client id and secret in one command. Treat the encoded value as the secret itself.
- A typed command lands in your shell history. Produce the encoding in a way that keeps the secret out of that file, or clear the entry afterwards.
- A config file inside a repository gets committed and shared. Keep credential-bearing config on your own machine, outside any repository. Where the client offers a secret prompt or a protected credential store, use it — the client's own documentation is what governs which of those it supports. For an automated environment, take the value from that platform's secret store rather than writing it into a file.
Create an MCP client in the portal and base64-encode
CLIENT_ID:CLIENT_SECRET:- macOS/Linux:
echo -n "CLIENT_ID:CLIENT_SECRET" | base64 - PowerShell:
[Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes("CLIENT_ID:CLIENT_SECRET"))
- macOS/Linux:
Open MCP Servers → Configure MCP Servers (this edits
cline_mcp_settings.json) and paste:{ "mcpServers": { "stackjack": { "disabled": false, "timeout": 60, "type": "streamableHttp", "url": "https://mcp.stackjack.io/mcp", "headers": { "Authorization": "Basic <BASE64_OF_CLIENT_ID:CLIENT_SECRET>" } } } }
If you use the Cline CLI, its MCP configuration lives at ~/.cline/mcp.json — the same server entry shape applies there.
Supported alternative: browser OAuth
Recent Cline builds can also authenticate in the browser. This is supported, but it is not the first-run lane StackJack's setup wizard shows for Cline:
- In the Cline panel, open MCP Servers → Remote Servers.
- Enter a name (for example "stackjack") and
https://mcp.stackjack.io/mcp, with transport Streamable HTTP. - Select Add Server, then Authenticate, and sign in with your normal StackJack account.
Cline's OAuth sign-in is not yet officially documented, and re-authentication after a token expires can be unreliable. If it stops working, return to the generated-credential path above.
Tool limits
Cline does not publish a hard MCP tool cap, but StackJack can expose hundreds of tools depending on your connectors and plan. With a generated credential, pick a client with a restricted tool selection so Cline only sees what it needs, or switch StackJack to compact catalog mode so it serves a small tool list and Cline discovers the rest on demand. An admin must first enable catalog modes for your organization on the Settings page; until then StackJack serves the full tool list. See Choosing tools for each client and managing harness tool limits.
Troubleshooting
- Re-authentication fails after the token expires — a known rough edge in Cline's OAuth alternative; switch to the generated-credential path.
- Sign-in says no account was found — sign up in the portal first, or ask your team admin for an invite.
- For anything else, see Connection troubleshooting.