Connect Wathba to your coding agent

Use one read-only MCP connection. Your browser handles member approval; the host stores its OAuth token outside model context.

Read-only coding-agent access

Connect your AI coding agent

Your agent can read your projects, enabled services, pinned integration guides, operation schemas, and troubleshooting. It cannot create environments, manage API keys, approve production, or run billable operations.

OAuth · mcp:read

Wathba MCP endpoint

https://api.wathba.info/mcp

OAuth tokens stay in the MCP host and credentials never enter model context.

Works with Replit, Claude Code, Codex, MCP Inspector, and any Streamable HTTP MCP host that supports OAuth.

Integration updates need additional access when connecting your agent. It must explain the change, keep a working fallback, and ask for your confirmation before each update.

Quick safety test

  1. Approve read-only access in the Wathba browser window.
  2. Confirm the host discovers exactly eight Wathba tools.
  3. Run list_projects, then request a Sandbox guide for Java, Go, or your repository stack.
  4. Confirm create_project is the only tool that can change anything, that it asks for separate approval, and that no API-key value appears in any result.
Open setup and testing guide

Agent-managed integration updates

To manage API upgrades, request mcp:read and mcp:api-contracts:upgrade in a new OAuth connection. Existing connections do not gain this permission automatically. Wathba then exposes inspect_api_upgrade, preview_api_upgrade, prepare_api_upgrade, apply_api_upgrade and rollback_api_upgrade. The agent must test both app versions, preserve a deployable fallback, prepare a scoped plan and ask you to confirm the exact update and live-app risk in your conversation. No second portal confirmation is required. Wathba records the authenticated agent’s attestation; it cannot independently verify the conversation. Never retry an uncertain payment with a different API version or key.

Host setup

Replit

Open Replit Integrations, add a custom remote MCP server, and enter the endpoint below. Replit opens Wathba for OAuth approval.

https://api.wathba.info/mcp

Claude Code app

In the Claude Code app, open Settings → Connectors, choose Add custom connector, name it Wathba, paste the endpoint below, and connect.

https://api.wathba.info/mcp
Open Claude Connectors

Claude Code CLI

Run the command once for your user account. Then run /mcp inside Claude Code, choose Wathba, and approve the read-only access in your browser.

claude mcp add --transport http --scope user wathba https://api.wathba.info/mcp

Codex app

Open the Wathba plugin in the Codex Plugins Directory — not Settings → Connections. Confirm the official Wathba logo and publisher, install it, then approve sign-in in your browser.

Open Wathba plugin

Codex CLI

Run these commands once to add Wathba and start the browser sign-in flow. Review and approve the read-only access yourself.

codex mcp add wathba --url https://api.wathba.info/mcp
codex mcp login wathba

Any MCP host

For any other client, choose Streamable HTTP, paste the endpoint, and let the client discover Wathba's OAuth metadata. The client must support Authorization Code + PKCE and Dynamic Client Registration or Client ID Metadata Documents.

https://api.wathba.info/mcp

Test with MCP Inspector

Start the official Inspector, select Streamable HTTP and the Modern (2026-07-28) protocol, enter the endpoint, connect through OAuth, then inspect Tools. Do not add an MCP-Protocol-Version custom header; the Inspector sends it.

npx @modelcontextprotocol/inspector

Acceptance checks

  1. Tools lists exactly eight tools: list_projects, get_project_setup, list_project_services, get_service_integration_docs, get_service_operations, get_service_troubleshooting, recommend_services_for_repository, and create_project. create_project works only after you separately approve projects:create.
  2. Wathba speaks MCP protocol 2026-07-28 (hosts that only support earlier revisions still connect) and exposes no resources. Every tool result, including errors, is one JSON object in structuredContent.
  3. list_project_services separates configuredServices from availableServices. You enable a service yourself on the portal page it links to; MCP never enables services.
  4. A project owned by another member is denied.
  5. Java, Go, PHP, .NET, Python, cURL, JavaScript, TypeScript, and other stacks return direct HTTP guidance; JavaScript/TypeScript may also use a supported SDK.
  6. No result contains an API key, provider credential, secret handle, or mutation instruction.
  7. There are no tools for creating environments, managing keys, approving production, or sending OTP/payment/shipping calls.

Useful first prompt

Use Wathba to list my projects. Ask me which project and service I mean, inspect my repository locally to identify its language and HTTP stack, then read the pinned Sandbox integration guide. Do not request, display, or manage any API key.