01
Codex
Put this native Codex MCP configuration in ~/.codex/config.toml; it uses the preregistered local callback.
[mcp_servers.flock-prod]
url = "https://mcp.flocksynthetics.com/mcp"
startup_timeout_sec = 350
tool_timeout_sec = 350
required = false
[mcp_servers.flock-prod.oauth]
client_id = "flock-codex"
callback_url = "http://localhost:8765/callback"
callback_port = 8765
Read-only login
codex mcp login flock-prod --scopes "https://mcp.flocksynthetics.com/mcp/read"
Read + test opt-in
codex mcp login flock-prod --scopes "https://mcp.flocksynthetics.com/mcp/read,https://mcp.flocksynthetics.com/mcp/test"
Leave oauth_resource unset. Use the first command for read-only access; use the second only when you explicitly want launch, retry, and cancel actions. Keep required = false for normal setup; use the per-run -c mcp_servers.flock-prod.required=true override only for a deliberate cold-start acceptance check. Keep this environment in its own flock-prod entry; do not overwrite another Flock environment's connection.
02
Claude Code
Add one HTTP server entry, then let Claude Code open the fixed local callback.
Read-only setup
claude mcp add-json flock-prod \
'{"type":"http","url":"https://mcp.flocksynthetics.com/mcp","oauth":{"clientId":"flock-claude","callbackPort":8766,"scopes":"https://mcp.flocksynthetics.com/mcp/read"}}'
claude mcp login flock-prod --no-browser
Read + test setup
claude mcp add-json flock-prod \
'{"type":"http","url":"https://mcp.flocksynthetics.com/mcp","oauth":{"clientId":"flock-claude","callbackPort":8766,"scopes":"https://mcp.flocksynthetics.com/mcp/read https://mcp.flocksynthetics.com/mcp/test"}}'
claude mcp login flock-prod --no-browser
The scopes value is space-separated. If flock-prod already exists, update that entry rather than adding a duplicate. Keep each Flock environment in a distinct entry. Scope changes require disconnecting the old grant in Flock Settings → Connected tools and consenting again.
03
Other clients
Use Streamable HTTP OAuth with PKCE and a preregistered client ID and callback.
server URL: https://mcp.flocksynthetics.com/mcp
read scope: https://mcp.flocksynthetics.com/mcp/read
test scope (opt-in): https://mcp.flocksynthetics.com/mcp/test
Automatic arbitrary dynamic client registration is not supported. Flock does not issue a secret or API key for this connection.