One prompt pairs any MCP client with your workspace. Nothing to install, no secret to copy by hand.
01
Generate a setup prompt
Sign in to your workspace and open Agents, then press Generate setup prompt. Out comes a short block of text carrying a one-time setup code: single-use, and good for 15 minutes. Generate a fresh one whenever you need it.
02
Paste it into your agent
Paste the prompt into Claude Code, Cursor, Codex, Copilot — or any other MCP client that can make an HTTP request and edit its own configuration. The agent spends the code on its own credential, registers Aptarium's hosted MCP server, verifies the connection, and tells you what it configured. You never handle the secret: the code dies on first use and the credential goes straight into the agent's config file.
The instructions the agent follows are public — read them at Agent instructions before you paste, if you would rather see the whole handshake first.
03
Connect the tools it should read
Open Connectors in your workspace and connect your own account for each tool a readout should read. Reads run through the connecting person's own account, so this is the one step nobody — no agent, no admin — can do on your behalf.
Scoped, revocable, expiring
A paired agent gets data:read, apps:read and apps:deploy: enough to publish an apt, never enough to widen who can see one. share:manage stays an explicit opt-in. Credentials expire after 90 days, are listed under Your credentials on the Agents page, and revoking one fails its next call closed.
Alternative
Pair from the terminal
The CLI does the same job for people who would rather stay in a shell — it signs in with Google, detects the agent installed on this machine, installs Aptarium's skills and MCP configuration, mints the credential and verifies MCP initialization. One line installs it; the origin is baked in:
curl -fsSL https://staging.patchbraid.info/install.sh | sh
Then pair. --server is required on any deployment that is not the CLI's compiled-in default — https://staging.patchbraid.info is this one:
Use --share only when the agent should manage existing Aptarium sharing. The command never prints its secret. Rerunning rotates the credential; a failed local write restores the previous config and revokes the new token. Once signed in, --server is remembered and every later command (deploy, connect, snapshot) omits it.