Search documentation

Search the Fumadocs-backed documentation index.

MCP with an API key

Connect an MCP client that cannot sign in with OAuth, such as the GitHub Copilot cloud agent, using a Fiveonefour API key.

Most MCP hosts sign in to Fiveonefour's MCP server with OAuth, which stays the default (see MCP install). Some clients cannot run an OAuth sign-in and only send a fixed header. The GitHub Copilot cloud agent is one of them. These clients can authenticate with your API key instead, sent as Authorization: Bearer <API_KEY>.

Not yet available for every account

API-key access to the MCP server is being rolled out and is off by default. Until it is enabled for your account, the MCP server answers 401 to an API key. OAuth sign-in is unaffected.

What the key can do

  • The key acts as you, in the organizations you belong to. If it was created for specific organizations, it is limited to those.
  • Only personal keys work. Organization keys, temporary-account keys and run-scoped test tokens are refused, and so is a personal key when any of its organizations is a temporary account that has not been claimed yet.
  • The key stops working if your account is banned, locked or deleted.
  • A revoked or expired key stops working on the next request. Revoke a key under Manage → API keys or with ax api-key revoke.
  • Requests are rate-limited per key. Over the limit, the server answers 429 with a Retry-After header.
  • cli_auth_start is not available on an API-key connection, because it would mint another key. To sign in the CLI, set AX_API_KEY or run ax auth login.

Create a dedicated personal key for each client under Manage → API keys (see Admin and settings), so you can revoke one without affecting the others.

GitHub Copilot cloud agent

The Copilot cloud agent reads its MCP servers from your repository settings and sends headers built from COPILOT_MCP_ secrets.

1. Store the key as a Copilot secret

In the repository on GitHub, open Settings → Secrets and variables → Agents, and add a repository secret:

NameValue
COPILOT_MCP_AX_API_KEYYour Fiveonefour API key

Only Agents secrets whose names start with COPILOT_MCP_ are available to MCP configuration.

2. Add the MCP configuration

Open Settings → Copilot → MCP servers, and paste this into MCP configuration:

{
  "mcpServers": {
    "ax": {
      "type": "http",
      "url": "https://app.514.ax/mcp",
      "headers": {
        "Authorization": "Bearer $COPILOT_MCP_AX_API_KEY"
      },
      "tools": [
        "mcp_org_list",
        "mcp_org_get_current",
        "mcp_org_set_current",
        "experiment_list",
        "experiment_view",
        "experiment_query",
        "run_list",
        "run_view",
        "run_query"
      ]
    }
  }
}

The agent calls Fiveonefour's tools without asking first, so tools is an allowlist: list only the tools the agent needs. The example above is read-only. Add tools such as experiment_run only if you want the agent to start runs on your behalf. See the tool catalog for every tool name.

3. Allow the agent to reach Fiveonefour

If the repository uses the cloud agent's firewall with a custom allowlist, add app.514.ax under Settings → Copilot → Internet access → Custom allowlist (or the organization's custom allowlist). Without it, the agent cannot reach the MCP server.

4. Check the connection

Assign the agent an issue that needs Fiveonefour data, for example "List my Fiveonefour experiments". In the agent's session log, the MCP startup step lists the ax tools it loaded. A 401 there means the key was refused: check that the secret name matches the header, that the key is not revoked, and that API-key access is enabled for your account.