# Connect an AI client

> Verified against the product on 2026-10-05

## Choose an address

Yes, you can connect an AI client over MCP. Choose an address based on what the client should access.

| Address | What it can reach | Sign-in |
| --- | --- | --- |
| Team: `https://mcp.heycactus.ai/mcp` | Every product in your teamspace. With the access granted at sign-in, a client can read team pages, the code map, customer conversations, and investigations. | Sign in with a Cactus account or use a personal token. |
| Product: `https://mcp.heycactus.ai/p/<name>/mcp` | Without a token, published Help Center pages for that product. The Help Center must be public. A teammate who signs in at this address can also use their granted team access. | No sign-in is needed for published pages. Use team credentials only if you want team access. |

Use the product address without team credentials when you want the client limited to published pages. An unauthenticated client can search and read those pages and ask Cactus questions answered from them. It can’t use that access to read pages withheld from visitors or customer conversations. <!-- source: repo, path: rule/2f44e89e-5abf-4dfa-b7b1-e933ef4053c9 -->

- team
- product

*Use the product address without team credentials when you want the client limited to published pages.*

## Connect a client

1. In **Connect › AI clients**, select **Add a client** to open setup.
2. Under **Who is it for**, choose **Your team** or **Your users**.
3. Select the AI client you want to connect.
4. Use the address or configuration shown in its setup panel.

The setup panel gives you instructions for Claude Code, Cursor, VS Code, Claude, and ChatGPT. ChatGPT has separate web and desktop instructions. For another remote MCP client, the panel provides the address to add to that client.

### Claude

Select **Claude** in the setup panel and follow the connection steps shown there.

### Cursor

In the Cursor setup, select **Add to Cursor**. Cursor opens with the address filled in.

### Team sign-in or token

The team setup can ask you to sign in with your Cactus account. The launch action for Claude Code, Cursor, or VS Code can instead create a personal token and include it in the setup prompt. You’ll see the token once. <!-- source: repo, path: rule/4c47b732-fe59-449b-9606-f9fc05c350a5 -->

## Approve access

For a browser-based connection, sign in, then check the verified client host, requested access, and teamspace shown on the consent page.

1. On the consent page, check the client host, requested access, and teamspace.
2. On the consent page, select **Allow** only after checking those details. The client gets a grant for the listed access and acts with your access on that teamspace.

The access listed on the consent page tells you what this client can do. Approve only the access you want to give it. <!-- source: repo, path: rule/8022ef9d-a251-4d80-9a86-d9d17df0d2ff -->

## Deny a connection

On the consent page, select **Deny** to send your decision back to the AI client without granting access. <!-- source: repo, path: rule/8022ef9d-a251-4d80-9a86-d9d17df0d2ff -->

## Claim an agent

A headless agent gives you a link and a code. Check the agent, its requested access, and the teamspace. Only enter a code from an agent you started yourself. <!-- source: repo, path: rule/8022ef9d-a251-4d80-9a86-d9d17df0d2ff -->

1. Open the claim link and review the agent and requested access.
2. On the claim page, enter the code in **The code the agent showed you**.
3. Select **Give it my team**. The agent picks up its team token on its next check.

## Revoke access

Choose the action that matches how the client connected. In **Connect › AI clients**, select **Revoke** beside a personal token to stop it on the next call. <!-- source: repo, path: rule/2f44e89e-5abf-4dfa-b7b1-e933ef4053c9 -->

| Connection | What to do | What happens |
| --- | --- | --- |
| Browser sign-in | In **Connect › AI clients**, select **Disconnect** beside the client. | Its grant ends, so the client must sign in again to use Cactus. |
| Claimed agent | In **Connect › AI clients**, select **Disconnect** beside the agent. | The agent must be claimed again to use Cactus. |
| Personal token | In **Connect › AI clients**, select **Revoke** beside the token. | The token is refused on its next call. Its old value stays in the client’s configuration. |
| Connected-client record | Select **Forget** beside the record. | This removes the record only. The client keeps its access and appears again when it reconnects. |
