Connect your AI agent
Paste mcp.busymate.dev once. 454 tools. No API keys.
Pick
Cursor and VS Code in one click. Everyone else pastes the same URL and authorizes on first use.
Claude Code
Add the server from your terminal. The first tool call opens your browser to authorize.
- 01
Run the command below in your terminal — added to this project only by default; add
--scope userto make it available in every project. - 02
The first tool call opens your browser to sign in and authorize — approve, and Claude Code confirms the connection.
# Claude Code — add the server, then authorize in your browser:
claude mcp add --transport http busymate-devtools https://mcp.busymate.devVerify:Run claude mcp list (or /mcp inside Claude Code) — busymate-devtools shows as connected, and all 454 tools are ready to call.
Claude.ai & Claude Desktop
Settings → Connectors → Add custom connector, paste the URL, click Connect, and authorize in the browser. No file to edit.
- 01
Open Settings → Connectors, click + and choose Add custom connector.
- 02
Paste the URL below as the remote server URL and click Add — leave the OAuth Client ID / Secret fields blank, Busymate doesn't need them.
- 03
Claude opens your browser to sign in — approve, and the connector shows as connected.
https://mcp.busymate.devVerify:Open the connector again — it lists all 454 tools, and Claude can call them mid-conversation.
Cursor
One click adds it and authorizes over OAuth. Or add it by hand to ~/.cursor/mcp.json (global) or a project .cursor/mcp.json:
- 01
Click Add to Cursor for the one-click install, or add the block below to
~/.cursor/mcp.json(global) or a project's.cursor/mcp.jsonby hand. - 02
Open Cursor Settings → MCP and turn the server on if it isn't already enabled.
- 03
The first tool call opens your browser to authorize — Cursor completes the OAuth handshake itself, so there's no client ID or secret to paste.
{
"mcpServers": {
"busymate-devtools": {
"url": "https://mcp.busymate.dev"
}
}
}Verify:Cursor Settings → MCP lists busymate-devtools as enabled, with its tool count shown next to it.
VS Code (Copilot)
One click installs it into VS Code. Or add it by hand to a workspace .vscode/mcp.json (the root key is servers):
- 01
Click Install in VS Code for the one-click install, or add the block below to a workspace
.vscode/mcp.json— or run MCP: Open User Configuration to add it for every workspace instead. - 02
VS Code asks you to trust the server the first time — approve it, then click Start on the code lens above the entry (or run MCP: List Servers from the Command Palette).
- 03
VS Code opens your browser for the OAuth handshake — sign in and approve.
{
"servers": {
"busymate-devtools": {
"type": "http",
"url": "https://mcp.busymate.dev"
}
}
}Verify:Run MCP: List Servers from the Command Palette — busymate-devtools shows Running, with all 454 tools listed.
ChatGPT
Where developer-mode connectors are available: Settings → Connectors → Add, paste the URL, and authorize. Availability varies by plan.
- 01
Turn on developer-mode connectors — in ChatGPT Settings, search for Developer mode or Connectors (the exact menu has moved before; it needs a Plus, Pro, or Business plan and up, and a workspace admin can restrict it).
- 02
Add a custom connector and paste the URL below.
- 03
Authorize in the browser tab that opens.
https://mcp.busymate.devVerify:The connector lists as connected. Ask ChatGPT to use a Busymate DevTools tool and it should call one without error.
Any other MCP client
The Streamable-HTTP transport is standard — Continue, Cline, Zed, or your own bot use the same config. Point it at the URL:
- 01
Confirm your client speaks the Streamable HTTP transport (not stdio-only) and supports OAuth 2.1 with Dynamic Client Registration — most current clients do.
- 02
Point it at the URL below, in whichever config shape your client expects — the block is the common
mcpServersshape most clients read directly. - 03
Authorize the browser prompt on first use, same as every client above.
{
"mcpServers": {
"busymate-devtools": {
"url": "https://mcp.busymate.dev"
}
}
}Verify:A tools/list call returns all 454 tools once you've authorized.
What happens on
The whole OAuth 2.1 flow, demystified — four steps, all standard, no console to visit first.
- 01
Your client registers itself
Dynamic Client Registration (RFC 7591): the client POSTs its own metadata and receives a client id. There's nothing to create in a console first.
- 02
You authorize in the browser
A browser window opens on Busymate's own sign-in. You approve once; PKCE protects the code exchange end to end.
- 03
Tools appear
The client lists the tools and your agent starts calling them — as you, scoped to your role, with destructive tools confirm-gated.
- 04
The token keeps working
Refresh rotation keeps the grant alive, and the same token also authenticates REST, WebSockets and Edge Functions. Revoke it any time — every call it made is in your audit trail.
Your account,
Access is OAuth 2.1 with Dynamic Client Registration and PKCE — no pasted keys, no shared secret. The one token an agent receives authenticates every Busymate surface (MCP, REST, WebSockets, Edge Functions) and is scoped to your own role: an agent can only do what you could do in the dashboard.
- RBAC-scoped
- confirm-gated
- secrets redacted
OAuth 2.1, no keys
Dynamic client registration (RFC 7591) + PKCE (S256) + refresh rotation. Users authorize in the browser against Busymate's sign-in — there's no API key to paste or leak.
Scoped to your role
Every call is authorized by the database itself (RBAC). Destructive tools demand an explicit confirmation, and secret values are never returned — they're write-only and redacted.
Fully audit-logged
Every tool call — every agent, every action — lands in your account's audit trail, so you can always see what an agent did on your behalf.
Read more: PrivacyTermsthe RBAC & audit-trail model
What your agent can
If a human can do it in the UI, an agent can do it over MCP.
Capture & inspect traffic
Search, inspect, tag, export (HAR), summarize, and delete captured requests and responses — per device or across your whole fleet.
Control devices
List, rename, unpair, toggle the VPN, set a connection type, or route a device's egress through an upstream proxy.
Drive a remote browser
Raw Chrome DevTools Protocol passthrough — open, evaluate, screenshot, and snapshot a connected device's Chrome.
Automate phone farms
Android and iOS device-farm automation — tap, type, swipe, install, and manage app lifecycle, with live mirroring.
Script & shape requests
Sandboxed request/response scripts, auto-block rules, breakpoints, and paused domains — mutate or synthesize traffic in flight.
Run the platform
Roles & capabilities (RBAC), TestFlight beta admin, billing, a queryable audit trail, notifications, to-dos, workspaces, and BusyBro team memory.
If something
The answers below cover every first-connect snag we've actually seen — most are the protocol working as designed.
The endpoint answers 401 in my browser — is it down?
No — that's the spec working. A bare GET on mcp.busymate.dev returns 401 with the OAuth challenge, because the URL is the OAuth resource identifier your client reads to find the sign-in flow. MCP clients proceed from that challenge automatically.
My client lists the tools but every call fails.
Tool discovery is served before authentication; calling anything requires OAuth. Finish the browser authorization your client started (or trigger it again if the token was revoked), then retry the call.
The browser window never opened.
Most clients also print the authorization URL — copy it into any browser. The flow is a normal web sign-in and hands control back to the client when it finishes.
Should I use mcp.busymate.dev or mcp.busymate.net?
Use mcp.busymate.dev for new configs. The older mcp.busymate.net serves the same server permanently and OAuth issues host-matched metadata on whichever host you connected to — existing setups never break.
Claude Code says the server already exists.
Remove the old entry first — claude mcp remove busymate-devtools — then add it again. Your OAuth grant survives; you won't have to re-authorize.
Do I need separate credentials for a bot and my editor?
No. Each client registers itself and gets its own OAuth grant against your account — individually revocable, all acting under your one role, all visible in the audit trail.
Connect in under
Add mcp.busymate.dev, authorize once, call any of the 454 tools.