Linear
Configure the canonical Linear MCP server in ivar.json, synchronize provider configurations, and authenticate via public-client Dynamic Client Registration (DCR).
Linear provides an official remote MCP server at https://mcp.linear.app/mcp. It uses OAuth 2.0 with standard public-client Dynamic Client Registration (DCR) and PKCE. Because it operates as a public client, no client secret is required or supported.
This guide walks through configuring Linear in your hall manifest, generating provider files with ivar sync, authenticating providers, and troubleshooting.
1. Add Linear to ivar.json
Add the canonical http definition to the mcp list in ivar.json:
{
"$schema": "https://ivar.run/schema/4.json",
"name": "acme",
"version": 4,
"providers": {
"available": ["claude-code", "opencode", "omp"],
"default": "claude-code"
},
"mcp": [
{
"name": "linear",
"type": "http",
"url": "https://mcp.linear.app/mcp"
}
]
}Canonical manifest rules:
nameis the unqualified identifier:linear.typemust be canonicalhttp.urlishttps://mcp.linear.app/mcp.
2. Synchronize provider configurations
Run ivar sync to materialize provider-specific configuration files at the hall root:
ivar syncivar sync prefixes the server name with the hall name (acme-linear):
- Claude Code: writes
acme-linearto.mcp.json(type: "http"). - OpenCode: writes
acme-lineartoopencode.json(type: "remote"). - OMP: writes
acme-lineartomcp.json(type: "http").
3. Authenticate providers
Authenticate Linear using ivar mcp auth with the canonical server name (linear):
# Authenticate a specific provider
ivar mcp auth linear --provider claude-code
ivar mcp auth linear --provider opencode
ivar mcp auth linear --provider omp
# Or authenticate all configured providers in sequence
ivar mcp auth linear --all-providersProvider authentication behavior
Linear supports standard public-client DCR, allowing different providers to handle authentication according to their native capabilities:
| Provider | Authentication flow | Token storage |
|---|---|---|
| Claude Code | Native OAuth flow (claude mcp login acme-linear). Claude performs DCR and PKCE in the browser. | Claude credential store (opaque to Ivar). |
| OpenCode | Native OAuth flow (opencode mcp auth acme-linear). OpenCode registers dynamically with Linear. | OpenCode credential store (mcp-auth.json / OS keychain). |
| OMP | Generic Ivar internal registration + PKCE flow. Ivar performs DCR, completes the OAuth exchange, and stores credentials via omp auth-broker. | OMP profile credential binding (profile + endpoint). |
No manual client secret
Linear uses standard public-client Dynamic Client Registration (RFC 7591) and PKCE (RFC 7636). There is no static client secret to create in the Linear web UI or store in .ivar/secrets/mcp.env.
Generated OAuth metadata in ivar.json
When Ivar executes internal DCR and OAuth for OMP (or when discovering endpoint details), it may record generated public-client OAuth metadata in ivar.json.
Supported metadata fields:
client_id: Dynamic client identifier assigned by Linear DCR.token_url: OAuth 2.0 token endpoint URL.resource: Target protected resource indicator.client_secret_env: Omitted for public clients.
{
"name": "linear",
"type": "http",
"url": "https://mcp.linear.app/mcp",
"oauth": {
"client_id": "<generated_client_id>",
"token_url": "<discovered_token_endpoint>",
"resource": "<discovered_resource>"
}
}Troubleshooting
Dynamic registration failures
If automated DCR fails or times out during ivar mcp auth linear:
- Verify network connectivity to
https://mcp.linear.app/mcp. - Ensure no proxy or firewall is stripping authorization headers or blocking OAuth redirect callbacks on
localhost.
Claude Code permission prompt
When Claude Code launches a session, ensure acme-linear is enabled in your session allowlist:
{
"mcpServers": {
"acme-linear": {
"type": "http",
"url": "https://mcp.linear.app/mcp"
}
}
}Run claude mcp login acme-linear if prompted for re-authorization.
OMP token binding issues
OMP ties credentials to the combination of active profile and endpoint URL:
- Run
ivar mcp auth linear --provider ompto refresh the registration and token broker binding. - Ensure the
token_urlpersists inivar.jsonunder the server'soauthmetadata block so OMP can refresh tokens.