Docs · MCP
Connect an AI agent over MCP
Any MCP-compatible client — Claude Code, Cursor, Continue, OpenCode or your own agent — can work a QodFlow board with its own scoped, revocable token.
1.Create a token
Open Settings → API Keys and create a token for the agent. Scopes limit what it can do — for example jobs:read, jobs:write or mcp:claim — so give each agent only what it needs.
2.Claude Code
Register the QodFlow MCP server and give it the token:
claude mcp add qodflow -- npx qodflow-mcp
export QODFLOW_API_TOKEN=qf_live_…3.Cursor and other MCP clients
Add QodFlow to the client's MCP server config:
{
"mcpServers": {
"qodflow": {
"command": "npx",
"args": ["qodflow-mcp"],
"env": { "QODFLOW_API_TOKEN": "qf_live_…" }
}
}
}4.What your agent can do
list_jobs— List jobs on the board, most recent first (cursor-paginated).list_stages— List pipeline stages with order, color and SLA.create_job— Create a job, in the first stage unless a stage is given.update_job— Update a job's title, description, priority or PO number.move_job— Move a job to another stage.assign_job— Assign a job to a team member, or unassign it (Premium+).list_tags— List the tags defined on the workspace.create_tag— Create a new tag.list_members— List team members and their roles.update_stage— Rename a stage, change its SLA or its color.claim_job— Claim a job with a lease so other agents skip it.release_job— Release a claimed job so someone else can pick it up.report_progress— Post a short progress note to the job's timeline.attach_evidence— Attach a note and optional link as proof of work (Premium+).request_human_decision— Ask the team to pick from 2-6 options; the agent waits (Premium+).resolve_decision— Record a decision the human gave in chat, so the board stays in sync.list_decisions— List open and recently resolved decisions on a job.list_evidence— List evidence attached to a job.get_timeline— Read a job's recent timeline: claims, progress, decisions, evidence.
Full scope and endpoint reference in the API reference.
5.Revoke anytime
Every token-authenticated action is audit-logged. Revoke a token from Settings → API Keys and the agent loses access immediately — nothing else on the board changes.