Configure through MCP
Connect your coding assistant to read, validate and propose Warpway configuration.
Connect your coding assistant to Warpway to read current policy, validate changes and prepare a configuration proposal on GitHub.
Connect
- Sign in to your organization and open Settings → MCP. Owners and Admins can create tokens.
- Create a token with Read, validate and propose configuration, or choose Read and validate only. Copy it when shown; Warpway stores only its hash. Tokens expire after 30 or 90 days.
- Add
https://app.warpway.ai/api/mcpto a client that supports Streamable HTTP with anAuthorization: Bearer YOUR_TOKENheader. Keep the token in your client's secret storage.
For Codex, add this to your host's config.toml:
[mcp_servers.warpway]
url = "https://app.warpway.ai/api/mcp"
bearer_token_env_var = "WARPWAY_MCP_TOKEN"Make WARPWAY_MCP_TOKEN available to the environment running Codex, using the token from Settings. Reconnect the MCP server after configuring it. See the official OpenAI MCP documentation for client setup. This endpoint uses bearer tokens; it does not offer an OAuth sign-in flow. Clients that accept only OAuth connections need a bearer-capable connection method.
Ask your assistant
Read the existing Warpway configuration for our API repository. Require security review for authentication changes and route billing questions to our product owner's Slack user ID. Preserve the existing policy, validate the YAML and prepare a configuration proposal.
Your assistant should read the repository and existing policy before generating rules. Use your actual GitHub/Slack identities; don't invent owner IDs. Provide any business rules the code alone cannot establish.
Available tools
| Tool | What it does |
|---|---|
warpway_list_repositories | Lists repositories in the token's organization. |
warpway_get_config | Reads current base-branch YAML from GitHub, org/repo settings, the config schema and custom lens references. Returns baseSha. |
warpway_validate_config | Runs Warpway's YAML and semantic validation without changing anything. |
warpway_propose_config | Validates a complete YAML draft and queues a proposal. Pass baseSha as expectedBaseSha. Requires a write token and the Team trial or a paid plan. |
warpway_get_proposal | Returns the proposal status and GitHub link. |
If the App has Contents: write, it opens a pull request. With the minimum read-only installation, it prepares a GitHub edit link and instructions for you to commit the file and open the PR. It does not silently increase App permissions. Repeated identical requests reuse a pending proposal. A changed base branch rejects a stale draft; read the latest configuration and propose again.
Permissions and when changes apply
Each token is limited to one organization and to its creator's current administrator access. Revocation, expiry, removal from the organization, or loss of administrator permissions prevents further calls. A read token does not expose the proposal tool.
MCP does not merge pull requests, connect Slack, charge a subscription, change organization locks or enable Owner trust/auto-approval switches. Organization locks and trust limits continue to apply. Review policy in .warpway.yml takes effect after it is merged into the trusted base branch. Configuration reference.
Revoke a token from Settings → MCP to disconnect that client immediately. Only your own tokens are listed there. Organization deletion removes its tokens and proposals.
Something unclear or missing? Email marcus@cmglabs.ai.