Clients that support OAuth register themselves with OnlyX automatically; you never need a client ID or secret.
Windsurf
Windsurf’s Cascade agent reads MCP servers frommcp_config.json: ~/.codeium/windsurf/mcp_config.json in classic Windsurf, or ~/.config/devin/mcp_config.json (%APPDATA%\devin\mcp_config.json on Windows) in newer Devin Desktop builds. Open it from Cascade’s MCP settings and add:
- OAuth
- API key
mcp_config.json
Gemini CLI
- OAuth
- API key
--scope user, the server is added to the current project only (.gemini/settings.json). In a settings file, use httpUrl (not url) for OnlyX:
~/.gemini/settings.json
OpenAI Codex CLI
- OAuth
- API key
/mcp lists connected servers.
Any other client
Most clients accept a JSON block like this. Adjust the key names to your client (url, serverUrl or httpUrl; mcpServers or servers):
headers if your client supports OAuth for remote servers. If your client only supports local (stdio) servers, it cannot connect to OnlyX directly yet.
Test the server yourself
When a client will not connect, check the server and your key directly. This sends an MCPinitialize request:
200with aresultnaming the OnlyX server: the server and your key work; the problem is in the client’s configuration.401: the credential was not accepted. Check the key, or sign in again. OnlyX’s401carries aWWW-Authenticateheader pointing to its sign-in metadata, which is how OAuth clients find the login page.403: the request came from a browser page OnlyX does not recognize. Connect from the client itself.
npx @modelcontextprotocol/inspector, choose Streamable HTTP, enter https://mcp.onlyx.ai/mcp, and either sign in with OAuth or add your key as a Bearer token.
Next
- Using OnlyX with Claude and other assistants: recipes that work in any client.
- Tools: every tool.