Skip to main content
These five steps take you from a fresh install to an agent that can only reach what you allow — a server to expose, an agent to authorize, and a scoped grant between them. Install Steerholm first if you haven’t.

1. Add an MCP server

This registers the git MCP server — structured git tools (history, diffs, commits) your agent can’t get from a plain shell. It runs via uvx, which ships with uv. For remote servers and more, see Add a server.

2. Add an agent

Save the access key — it’s shown only once.

3. Grant access

This lets my-agent read commit history (git_log) — but only for repos under /home/user/projects/. Every other tool (git_commit, git_reset, …) is denied by default, so the agent can inspect history but structurally cannot change it.

4. Connect your agent

Point your agent at the endpoint, with the access key as the Bearer token. For example, Claude Code’s .mcp.json:
Each client stores this differently — see Add an agent for VS Code, Cursor, and OpenCode. The agent sees only the servers and tools its policy allows.
Configuring the agent with the key is the current manual step of adding an agent — Steerholm will set this connection up for you in a future release.

5. Verify it works

Confirm the server is running and see the tools it exposes:
Your agent should now list the tools its policy allows. If none appear, see Troubleshooting.

What happens at runtime

If the agent tries something unauthorized: