MCP Setup
FlightDesk runs an MCP (Model Context Protocol) server, so an AI assistant can read and manage your tasks, projects, plans, questions, releases and preview environments in conversation — and so an agent turn can report on itself without shelling out to the CLI.
One Kind of Token
There is only one kind of personal token, and it works for the CLI, the GraphQL API and MCP. Two pages create it:
- Settings → Personal → API Tokens — the general page. Creates the token, and also shows the CLI install commands and the Claude Desktop configuration.
- Settings → Personal → AI & MCP — the same tokens, presented for MCP: it generates one, shows the config to paste, and lists some of the tools. The AI & MCP entry is the last tab in the Personal tab strip, but it opens a standalone page at
/settings/airather than another Personal tab, so the tab strip is not shown once you are on it.
Use either. A token created on one page appears on the other, because they are the same list. Revoking it on either page revokes it everywhere.
Whichever you use, the token is shown once. An agent's key is a different thing — organization-scoped and minted with the agent user; see Agents and Orchestration.
Connecting Claude
The server speaks HTTP and authenticates with a bearer token:
{
"mcpServers": {
"flightdesk": {
"type": "http",
"url": "https://api.flightdesk.dev/api/mcp",
"headers": { "Authorization": "Bearer YOUR_TOKEN" }
}
}
}
Both settings pages render this block with the server URL already filled in for the deployment you are looking at — copy it from there rather than from here if you are not on flightdesk.dev.
What the Tools Cover
Around sixty tools, grouped below by what they are for. Note that the Available Tools card on the settings pages is a short hand-picked list of eleven, not the whole set — so neither that card nor this table is authoritative. The server's own tool list, which your MCP client fetches on connecting, is:
| Area | Tools |
|---|---|
| Orientation | list_organizations, list_members, list_projects, get_project, create_project, update_project |
| Tasks | list_tasks, get_task, get_task_by_session_id, create_task, update_task, update_task_status, add_timeline_event, add_task_comment, list_task_comments |
| Plans | get_plan, submit_plan, approve_plan, get_task_prompt |
| Questions | ask_question, list_questions, get_answers, withdraw_question, record_session_decision |
| Intake and triage | upsert_task_by_source, list_tasks_by_source, triage_new_request, clear_triage, task_status_report, attention_list |
| Initiatives and releases | list_initiatives, create_initiative, update_initiative, list_releases, get_release, create_release, update_release, stage_release, ship_release, link_initiative_release, move_unfinished_tasks |
| Dependencies | add_dependency, remove_dependency |
| Orchestration | save_project_orchestration, create_agent, rotate_agent_key, bind_agent, request_dispatch, list_dispatch_requests, poll_dispatch_requests, update_dispatch_request, report_progress, end_turn, transition_work_status |
| Hand-off | handoff_pull_request |
| Previews and secrets | get_preview_status, list_project_secrets, set_project_secrets, delete_project_secret |
What a Token Can and Cannot Do
A personal token acts as you, with your permissions in each organization you belong to. The tools whose own descriptions begin "Owner/admin" — create_agent, rotate_agent_key, save_project_orchestration — work through it only if you hold that role.
Some operations are refused to an agent key regardless of permissions, because they are human acts: approve_plan, and triage_new_request (clearing a new-request flag).
Digest recipients are not in this list, because there is no MCP tool for them. Reporting is configured in the app, at Settings → Organization → Reporting — see Notifications and Digests.
Secrets are write-mostly. list_project_secrets returns the keys a project has, never the values.
Housekeeping
Tokens show when they were created, when they were last used, and when they expire. Last used is the useful column: a token with no recent use is one you can revoke. Do that from either page, and rotate rather than reuse if a token has been through a transcript or a log.