Skip to main content
Adding an MCP-capable agent (Claude Code, VS Code, Cursor, OpenCode, etc.) to Steerholm is two steps: register it to get its access key, then point it at Steerholm. From then on it acts on the action plane as that agent, and every request is checked against its policy before anything reaches a server.
An agent sees no tools until you also grant it access — that’s a separate step, covered in Managing access.

1. Register the agent

This prints an access key (steer_sk_…) once — save it now; it’s the only time the full key is shown. holm show agent my-agent shows only the key prefix. Lost it? Issue a new one with holm rotate agent my-agent (the old key stops working immediately).

2. Point the agent at Steerholm

Every agent connects the same way, with two things:
  • Endpoint — http://127.0.0.1:4767/mcp
  • Header — Authorization: Bearer steer_sk_...
The rest is just where each agent keeps its config and what it names the entry.
Add the server with the CLI. Run this from your project — it writes to the project’s local scope by default; add --scope user to make it available in every project:
To share the server with a team, commit an .mcp.json at your project root instead:
The "type": "http" field is required. Claude Code reads a url entry with no type as a stdio server and skips it.
Steerholm binds to loopback over plain HTTP. Use the host and port from holm serve if you changed the defaults.
Copying the key into the agent is the current manual step. A future release will set this connection up for you (and launch agent sessions directly) — the model stays the same, the copy-paste goes away.

3. Verify

From Steerholm’s side, confirm the agent is registered and holds a key:
In the agent itself, the Steerholm connection should come up connected, with no auth error. It lists only the tools its policy allows — so a freshly added agent with no grants connects successfully but sees nothing yet. Grant it a server (see Managing access) and its tools appear. If the agent reports an authentication or connection error, head to Troubleshooting.

Rotate a key

Rotating issues a new access key and keeps all of the agent’s grants. The old key stops working immediately, so update the agent’s config with the new key afterward:

Remove an agent

Removes the agent, revokes its key, and deletes its policy: