How-to Guides

Connect a coding agent (MCP)

Point Claude Code, Cursor or any MCP client at Qualflare so it can read your suites, launches and defects — and create test cases — using the access token you already have.

Connect a coding agent (MCP)

Qualflare speaks MCP, so an AI coding agent can read your test data and create test cases while you work in your editor. It uses the same access token as the CLI and the same permissions — there is no separate MCP key to manage.

This is different from the Claude Code plugin, which drives the qf CLI from a chat window. The MCP server is a live connection to your project's data, and any MCP client can use it.


Before you start

You need:

  • An MCP-capable client — Claude Code, Cursor, or anything else that supports MCP
  • A Qualflare access token for the project you want to work on — see Access Tokens

The token decides everything: which project the agent sees, and what it may do there.


The connection details

Endpointhttps://api.qualflare.com/mcp
TransportStreamable HTTP
HeaderAuthorization: Bearer <your access token>

Claude Code

claude mcp add --transport http qualflare https://api.qualflare.com/mcp \
  --header "Authorization: Bearer YOUR_TOKEN"

Then ask it something like "which suites have the most failures this week?" — it will call the Qualflare tools to answer.

Cursor and other JSON-configured clients

Most clients take a JSON block like this (Cursor reads ~/.cursor/mcp.json):

{
  "mcpServers": {
    "qualflare": {
      "url": "https://api.qualflare.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_TOKEN"
      }
    }
  }
}

Client configuration differs — check your client's own MCP documentation for where the file lives and what it calls each field. The endpoint and the header are the same either way.

Your token is a credential. Prefer your client's secret storage or an environment variable over committing a config file that contains it, and revoke a token you have pasted somewhere shared.


What the agent can do

It sees your project through the same API the CLI uses — 16 read tools and 6 write tools. See MCP Server for the full list.

Reading: test suites and cases, steps, launches and their results, defects, milestones, test plans, and failure clusters.

Writing: create and update test cases, steps and defects. Nothing is deleted, and uploading results stays a CLI job.


What it may do depends on who created the token

Permissions come from the project role of the person who created the token, checked on every request:

That person's roleThe agent can
Viewerread everything in the project
Editor or aboveread, and create or update cases, steps and defects

Two consequences worth knowing:

  • A token is not restricted to reading. If its creator can write in the project, so can any agent holding that token — over MCP and over the API alike.
  • If that person's role is lowered or removed, the token loses that access immediately, because the role is re-read on every call rather than frozen when the token was made.

Troubleshooting

401 / "invalid or expired access token" — the token is wrong, revoked, or expired. Create a fresh one in Project Settings → Access Tokens.

403 / "no project access" — the token is valid, but its creator's role is too low for what the agent tried. Reading needs Viewer; creating or updating needs Editor.

The client connects but lists no tools — check the URL ends in /mcp and that the Authorization header is actually being sent; some clients need headers nested under the server entry, as shown above.

A write is refused with "not approved to write" — that is a Qualflare-internal token type, not yours. Use an access token created in Project Settings.