# OMP
> Setting up, authenticating, and running MCP servers in OMP with Ivar.
Source: https://ivar.run/docs/guide/mcp/providers/omp

import { Callout } from 'fumadocs-ui/components/callout';

OMP reads its MCP server configurations from `mcp.json` at the hall root. Unlike Claude Code and OpenCode, OMP does not have a native CLI command for MCP authentication (`omp mcp auth` / `login` does not exist). Ivar manages the OAuth lifecycle internally for OMP and binds credentials into OMP's broker store.

## Configuration & naming

`ivar` maps canonical server names from `ivar.json` (`figma`, `linear`) to hall-qualified keys (`<hall>-<server>`) in `mcp.json`.

- **Provider config path:** `mcp.json` (hall root)
- **Canonical vs. qualified names:** Declared as `figma` and `linear` in `ivar.json`; mapped to `acme-figma` and `acme-linear` in `mcp.json` (for a hall named `acme`).
- **OAuth auth blocks:** Generated MCP configuration for OAuth servers sets `"type": "oauth"` and requires a persisted `tokenUrl` (`token_url`).

### Generated `mcp.json`

```json title="mcp.json"
{
  "mcpServers": {
    "acme-linear": {
      "type": "http",
      "url": "https://mcp.linear.app/mcp",
      "auth": {
        "type": "oauth",
        "clientId": "<generated_client_id>",
        "tokenUrl": "<discovered-token-endpoint>"
      }
    },
    "acme-figma": {
      "type": "http",
      "url": "https://mcp.figma.com/mcp",
      "auth": {
        "type": "oauth",
        "clientId": "<generated_client_id>",
        "clientSecret": "${IVAR_MCP_ACME_FIGMA_SECRET}",
        "tokenUrl": "<discovered-token-endpoint>"
      }
    }
  }
}
```

## Authentication

Because OMP provides no direct MCP login command, all MCP authentication for OMP is performed via `ivar mcp auth`.

Ivar executes its internal OAuth PKCE workflow in the browser, exchanges tokens, and then imports the credentials into OMP using `omp auth-broker`, bound by profile and server endpoint.

### Linear

```sh
# Via Ivar (canonical name)
ivar mcp auth linear --provider omp
```

Ivar performs dynamic client registration against Linear, completes the PKCE flow, and binds the tokens to OMP via `omp auth-broker`.

### Figma

```sh
# Via Ivar (canonical name)
ivar mcp auth figma --provider omp
```

Ivar pre-registers an allowlisted client (`Codex`), stores the client secret in `.ivar/secrets/mcp.env`, executes the PKCE exchange, and binds the tokens to OMP via `omp auth-broker`.

### Authenticate all providers

To authenticate all configured providers for a server at once:

```sh
ivar mcp auth figma --all-providers

### Status inspection

OMP status is queried via `omp token`. Because OMP has no CLI `mcp list` command, `ivar mcp status --live` queries the local token broker and reports the source as `local`.

## OAuth ownership & credentials

| Aspect | Linear | Figma |
| --- | --- | --- |
| **OAuth ownership** | Ivar (internal OAuth PKCE) | Ivar (internal OAuth PKCE) |
| **Direct CLI command** | None (OMP has no native MCP login) | None (OMP has no native MCP login) |
| **Preregistration by Ivar** | Dynamic client registration (`/register`) | Yes (`client_name: "Codex"`) |
| **Credential storage** | `omp auth-broker` (profile + endpoint) | `omp auth-broker` (profile + endpoint) |
| **Secret location** | None | `.ivar/secrets/mcp.env` (`IVAR_MCP_ACME_FIGMA_SECRET`) |

## Related

- [Linear integration guide](/docs/guide/mcp/integrations/linear)
- [Figma integration guide](/docs/guide/mcp/integrations/figma)
- [MCP OAuth overview](/docs/guide/mcp/oauth)
- [MCP reference & schema](/docs/reference/mcp)
