agentleFS
Sign inSign up

Documentation

Connect an agent over MCP

Connecting over MCP

Agent clients read from agentleFS through the Model Context Protocol (MCP). The MCP server exposes tools like list_folders, retrieve_context, and filesystem navigation (list/read/…) — and enforces every call against the same grants you set in Permissions. Callers only ever see content they're authorized for.

Want your agent to do the setup? Tell it to read /connect.md — install instructions written for the agent itself.

Connecting as yourself

If a person is driving the client — Claude Code, Cursor, Claude Desktop — this is the path. There is no token to mint, paste, or rotate, and your access always reflects your current roles: change them in Permissions and the very next call sees it.

  1. 1Run this in your terminal:
    claude mcp add --transport http agentlefs https://agentlefsmcp-server-dev.up.railway.app/mcp
  2. 2Start claude and run /mcp, then choose agentlefs and authenticate.
  3. 3A browser window opens. Sign in and pick this organization — the same login you used for this console.
  4. 4Back in the terminal, /mcp now shows connected. Your agent can read everything you can.

Any other MCP client takes this URL directly — include the /mcp path.

https://agentlefsmcp-server-dev.up.railway.app/mcp
Claude Code MCP documentation

Stuck? Ask whoever runs this deployment, with what you tried and what came back.

Agent tokens — for agents, not people

A afs_… token exists for one reason: code that has no browser to redirect. Reach for it when the caller is an agent your application runs — an in-app assistant serving your users, a scheduled summarizer, a retrieval step inside your own product — plus the adjacent headless cases, CI jobs and scripts.

If a human is at the keyboard, you want browser sign-in above instead. A token is a long-lived secret you have to store and rotate; sign-in isn't.

Give each agent its own principal. In Permissions, create a principal for the agent, grant it only the roles that agent needs, then mint its token. Per-agent identity is what makes the audit trail attributable and lets you revoke one agent without touching the others. The token is shown once — treat it like a password.
Remote HTTP (Streamable HTTP) — afs_ header

POST to /mcp — one endpoint, the whole toolset. The token goes in a bearer header:

POST https://agentlefsmcp-server-dev.up.railway.app/mcp
Authorization: Bearer afs_your_token_here
Content-Type: application/json
{
  "mcpServers": {
    "agentlefs": {
      "url": "https://agentlefsmcp-server-dev.up.railway.app/mcp",
      "headers": {
        "Authorization": "Bearer afs_your_token_here"
      }
    }
  }
}
Every call is authorized and audited. Reads are filtered by the caller's grants — on the file, or on a folder above it — before results leave the server.