Skip to main content
Use your API’s MCP URL, such as https://vitalog-api.example.com/mcp. The UI address is where you sign in and review records; it is not the MCP endpoint. Open Account Settings → MCP Guide in Vitalog to copy configurations for your installation. The examples below use the example API hostname. Replace it when self-hosting.

Connect with OAuth

Add the MCP URL to a client that supports Streamable HTTP and MCP authorization. The client discovers the authorization server, registers or supplies its client metadata, and opens Vitalog’s consent page. Sign in with the root email and password, review the requesting client’s identity, callback destination and requested access, then approve. The client receives its token through the OAuth callback and token exchange. You do not need to create or paste an API key. Tokens expire after 30 days; reconnect after expiry. Revoke a connection from Account Settings → MCP Connections after verifying your root credentials.
Add this to ~/.codex/config.toml:
Run codex mcp login vitalog to sign in.
Other clients can use the same URL and OAuth discovery. Vitalog follows the MCP authorization specification independently of the client’s brand. See the OAuth contract for registration, PKCE, scopes and callback requirements.

OAuth authorization only

MCP accepts only OAuth access tokens granted through sign-in and consent. Personal API keys, the operator AUTH_KEY, and dashboard sessions cannot authenticate MCP. Read tools require health:read; record and goal changes require health:write. If you previously used an API key, remove its custom authorization header or bearer-token environment setting and reconnect through OAuth. REST integrations can keep using their API keys.

Tool discovery and calls

Vitalog uses stateless Streamable HTTP with JSON responses. For raw MCP POST requests, send Accept: application/json, text/event-stream. The official SDK negotiates the protocol version. Clients initialize, list tools and call the MCP tools; logging, discovery, reading, correction and goals share the REST domain service.

Troubleshooting

Check your client’s current documentation for client-specific connection controls: Codex, Claude Code, Cursor and VS Code.