# Linear
> Configure the canonical Linear MCP server in ivar.json, synchronize provider configurations, and authenticate via public-client Dynamic Client Registration (DCR).
Source: https://ivar.run/docs/guide/mcp/integrations/linear

import { Callout } from 'fumadocs-ui/components/callout';

Linear provides an official remote MCP server at `https://mcp.linear.app/mcp`. It uses OAuth 2.0 with standard public-client Dynamic Client Registration (DCR) and PKCE. Because it operates as a public client, **no client secret** is required or supported.

This guide walks through configuring Linear in your hall manifest, generating provider files with `ivar sync`, authenticating providers, and troubleshooting.

## 1. Add Linear to `ivar.json`

Add the canonical `http` definition to the `mcp` list in `ivar.json`:

```json title="ivar.json"
{
  "$schema": "https://ivar.run/schema/4.json",
  "name": "acme",
  "version": 4,
  "providers": {
    "available": ["claude-code", "opencode", "omp"],
    "default": "claude-code"
  },
  "mcp": [
    {
      "name": "linear",
      "type": "http",
      "url": "https://mcp.linear.app/mcp"
    }
  ]
}
```

Canonical manifest rules:
- `name` is the unqualified identifier: `linear`.
- `type` must be canonical `http`.
- `url` is `https://mcp.linear.app/mcp`.

## 2. Synchronize provider configurations

Run `ivar sync` to materialize provider-specific configuration files at the hall root:

```sh
ivar sync
```

`ivar sync` prefixes the server name with the hall name (`acme-linear`):
- **Claude Code**: writes `acme-linear` to `.mcp.json` (`type: "http"`).
- **OpenCode**: writes `acme-linear` to `opencode.json` (`type: "remote"`).
- **OMP**: writes `acme-linear` to `mcp.json` (`type: "http"`).

## 3. Authenticate providers

Authenticate Linear using `ivar mcp auth` with the canonical server name (`linear`):

```sh
# Authenticate a specific provider
ivar mcp auth linear --provider claude-code
ivar mcp auth linear --provider opencode
ivar mcp auth linear --provider omp

# Or authenticate all configured providers in sequence
ivar mcp auth linear --all-providers
```

### Provider authentication behavior

Linear supports standard public-client DCR, allowing different providers to handle authentication according to their native capabilities:

| Provider | Authentication flow | Token storage |
| --- | --- | --- |
| **Claude Code** | Native OAuth flow (`claude mcp login acme-linear`). Claude performs DCR and PKCE in the browser. | Claude credential store (opaque to Ivar). |
| **OpenCode** | Native OAuth flow (`opencode mcp auth acme-linear`). OpenCode registers dynamically with Linear. | OpenCode credential store (`mcp-auth.json` / OS keychain). |
| **OMP** | Generic Ivar internal registration + PKCE flow. Ivar performs DCR, completes the OAuth exchange, and stores credentials via `omp auth-broker`. | OMP profile credential binding (`profile` + `endpoint`). |

<Callout type="info" title="No manual client secret">
  Linear uses standard public-client Dynamic Client Registration (RFC 7591) and PKCE (RFC 7636). There is no static client secret to create in the Linear web UI or store in `.ivar/secrets/mcp.env`.
</Callout>

## Generated OAuth metadata in `ivar.json`

When Ivar executes internal DCR and OAuth for OMP (or when discovering endpoint details), it may record generated public-client OAuth metadata in `ivar.json`.

Supported metadata fields:
- `client_id`: Dynamic client identifier assigned by Linear DCR.
- `token_url`: OAuth 2.0 token endpoint URL.
- `resource`: Target protected resource indicator.
- `client_secret_env`: Omitted for public clients.

```json title="ivar.json (fragment with generated public-client OAuth metadata)"
{
  "name": "linear",
  "type": "http",
  "url": "https://mcp.linear.app/mcp",
  "oauth": {
    "client_id": "<generated_client_id>",
    "token_url": "<discovered_token_endpoint>",
    "resource": "<discovered_resource>"
  }
}
```

## Troubleshooting

### Dynamic registration failures
If automated DCR fails or times out during `ivar mcp auth linear`:
- Verify network connectivity to `https://mcp.linear.app/mcp`.
- Ensure no proxy or firewall is stripping authorization headers or blocking OAuth redirect callbacks on `localhost`.

### Claude Code permission prompt
When Claude Code launches a session, ensure `acme-linear` is enabled in your session allowlist:
```json title=".mcp.json"
{
  "mcpServers": {
    "acme-linear": {
      "type": "http",
      "url": "https://mcp.linear.app/mcp"
    }
  }
}
```
Run `claude mcp login acme-linear` if prompted for re-authorization.

### OMP token binding issues
OMP ties credentials to the combination of active profile and endpoint URL:
- Run `ivar mcp auth linear --provider omp` to refresh the registration and token broker binding.
- Ensure the `token_url` persists in `ivar.json` under the server's `oauth` metadata block so OMP can refresh tokens.

## Related documentation

- [MCP Overview](/docs/guide/mcp)
- [Claude Code Provider](/docs/guide/mcp/providers/claude-code)
- [OpenCode Provider](/docs/guide/mcp/providers/opencode)
- [OMP Provider](/docs/guide/mcp/providers/omp)
- [Figma Integration Guide](/docs/guide/mcp/integrations/figma)
- [OAuth & Credentials Guide](/docs/guide/mcp/oauth)
- [MCP Reference](/docs/reference/mcp)
