OMP
Setting up, authenticating, and running MCP servers in OMP with Ivar.
OMP reads its MCP server configurations from mcp.json at the hall root. Unlike Claude Code and OpenCode, OMP does not have a native CLI command for MCP authentication (omp mcp auth / login does not exist). Ivar manages the OAuth lifecycle internally for OMP and binds credentials into OMP's broker store.
Configuration & naming
ivar maps canonical server names from ivar.json (figma, linear) to hall-qualified keys (<hall>-<server>) in mcp.json.
- Provider config path:
mcp.json(hall root) - Canonical vs. qualified names: Declared as
figmaandlinearinivar.json; mapped toacme-figmaandacme-linearinmcp.json(for a hall namedacme). - OAuth auth blocks: Generated MCP configuration for OAuth servers sets
"type": "oauth"and requires a persistedtokenUrl(token_url).
Generated mcp.json
{
"mcpServers": {
"acme-linear": {
"type": "http",
"url": "https://mcp.linear.app/mcp",
"auth": {
"type": "oauth",
"clientId": "<generated_client_id>",
"tokenUrl": "<discovered-token-endpoint>"
}
},
"acme-figma": {
"type": "http",
"url": "https://mcp.figma.com/mcp",
"auth": {
"type": "oauth",
"clientId": "<generated_client_id>",
"clientSecret": "${IVAR_MCP_ACME_FIGMA_SECRET}",
"tokenUrl": "<discovered-token-endpoint>"
}
}
}
}Authentication
Because OMP provides no direct MCP login command, all MCP authentication for OMP is performed via ivar mcp auth.
Ivar executes its internal OAuth PKCE workflow in the browser, exchanges tokens, and then imports the credentials into OMP using omp auth-broker, bound by profile and server endpoint.
Linear
# Via Ivar (canonical name)
ivar mcp auth linear --provider ompIvar performs dynamic client registration against Linear, completes the PKCE flow, and binds the tokens to OMP via omp auth-broker.
Figma
# Via Ivar (canonical name)
ivar mcp auth figma --provider ompIvar pre-registers an allowlisted client (Codex), stores the client secret in .ivar/secrets/mcp.env, executes the PKCE exchange, and binds the tokens to OMP via omp auth-broker.
Authenticate all providers
To authenticate all configured providers for a server at once:
ivar mcp auth figma --all-providers
### Status inspection
OMP status is queried via `omp token`. Because OMP has no CLI `mcp list` command, `ivar mcp status --live` queries the local token broker and reports the source as `local`.
## OAuth ownership & credentials
| Aspect | Linear | Figma |
| --- | --- | --- |
| **OAuth ownership** | Ivar (internal OAuth PKCE) | Ivar (internal OAuth PKCE) |
| **Direct CLI command** | None (OMP has no native MCP login) | None (OMP has no native MCP login) |
| **Preregistration by Ivar** | Dynamic client registration (`/register`) | Yes (`client_name: "Codex"`) |
| **Credential storage** | `omp auth-broker` (profile + endpoint) | `omp auth-broker` (profile + endpoint) |
| **Secret location** | None | `.ivar/secrets/mcp.env` (`IVAR_MCP_ACME_FIGMA_SECRET`) |
## Related
- [Linear integration guide](/docs/guide/mcp/integrations/linear)
- [Figma integration guide](/docs/guide/mcp/integrations/figma)
- [MCP OAuth overview](/docs/guide/mcp/oauth)
- [MCP reference & schema](/docs/reference/mcp)