Connect with OAuth
For step-by-step installation instructions for specific coding agents, like Claude Code, Cursor, Codex, VS Code, Pi, and OpenCode, see the coding agent setup guide. OAuth is the default way to connect. Your MCP client opens Nango in a browser so you can sign in and approve access. You do not need to create or store a credential in the client.-
Add the Management MCP server to a client that supports Client ID Metadata Documents (CIMD):
- Start the clientβs OAuth flow.
- Sign in to Nango in the browser and approve the authorization request.
- Return to the client. It stores and refreshes the OAuth credentials for you.
Select an environment
OAuth authorizes the MCP client for your Nango account. Most tools require anenvironment argument containing the name of the environment in which to run the operation.
Call environments_list first to get the environments you can access. The server checks your Nango user permissions in the selected environment for every tool call. All environment-scoped tools require permission to read that environmentβs settings, plus any permission listed below.
Tools
Environments
Use the Environments tool to list the Nango environments available to your user. It does not take anenvironment argument.
Documentation
Use the Documentation tools to search the Nango documentation and read complete pages from Mintlifyβs virtual documentation filesystem. Start withdocs_search for broad or conceptual queries, then use docs_query_filesystem to read a relevant .mdx path or perform an exact text search.
These tools require no additional environment operation permission. If Mintlify rate-limits a request, the tool error points to the public Nango documentation MCP at https://nango.dev/docs/mcp so you can connect to it directly.
Providers
Use the Provider tools to inspect the public provider catalog. Setinclude_templates to true to include the providerβs available function templates in the result.
These tools require no additional environment operation permission.
Connect sessions
Use the Connect Session tools to start an authorization flow for an end user.Integrations
Use the Integrations tools to inspect and manage integrations in the authenticated Nango environment.Connections
Use the Connections tools to inspect connections in the authenticated Nango environment. Connection list results never include credentials. Getting a connection only includes credentials when the caller has the credential-reading permission.Actions
Use the Actions tool to trigger an action function synchronously for a connection. Provide the integration ID, connection ID, and action name. The JSON input is optional. The tool returns the actionβs JSON result in thedata field.
Syncs
Use the Sync tools to set sync state or trigger syncs for an integration in the authenticated Nango environment. You can optionally limit either operation to one connection and select named sync variants. Triggering can run a full reset and clear existing synced records.Functions
Use the Functions tools to inspect and deploy template functions in the authenticated Nango environment. Useget_deployment_status to check whether a deployment has finished.
Logs
Use the Logs tools to find activity in the authenticated Nango environment and inspect the messages for a specific operation.
See Observability for more information about Nango logs.
Use an API key instead
An Environment API key is an option for non-interactive clients and clients that do not support CIMD. It authenticates the client to one Nango environment, soenvironments_list is not exposed and other tool calls do not take an environment argument.
Create an Environment API key in Environment Settings > API Keys, then configure the MCP client to send it as a Bearer token:
The permissions in the tables above are the required API key scopes. The
environment:mcp scope is not required.
API key authentication also exposes these tools:
proxy_request supports GET, POST, PUT, PATCH, and DELETE, along with query parameters, headers, request bodies, base URL overrides, and up to 5 retries. It returns the provider response status, headers, and JSON or UTF-8 text body up to 5 MB (5,000,000 bytes). Unsafe JSON integers and high-precision decimals are returned as strings. Binary responses, other character encodings, and larger responses return a tool error. Use the matching Proxy HTTP API endpoint for those responses.
Keep the API key server-side and only configure it in MCP clients you trust. Do not expose it in client-side code, logs, or URLs.