Cowboy MCP 1.7.2: one-click sign-in for Claude Code, Codex, Gemini CLI, Cursor, VS Code and Opencode
Until now, the Claude and ChatGPT apps connected with one click, while terminal tools and code editors needed an API key: generate it, copy it before it disappears, paste it into a command or a config file, and keep it somewhere safe. In 1.7.2 every app connects with the same one-click sign-in. Run one command or click one button, click Approve on your own site, and you're connected. It takes about two minutes.
What one-click sign-in gets you
- Nothing to copy, store, or leak. There's no key sitting in your shell history, a dotfile, or a project repo, waiting to be committed by accident.
- You decide before anything happens. The sign-in page on your site names the app that is asking, and you choose what it can do: everything, read-only, or a hand-picked list of tools. Nothing is allowed until you click Approve.
- One app, one connection. Each app gets its own row on the Connections tab. Change what it can do or revoke it in one click, and every other app keeps working.
- The same steps everywhere. Learn it once for Claude and it works the same in your terminal, your editor, and on a local development site.
How to connect each app
How you start depends on the app:
- Claude Code: two lines. The second one opens the sign-in page.
claude mcp add --transport http your-site https://your-site.com/wp-json/cowboy-mcp/v1/endpoint claude mcp login your-site - Codex: one line, and Codex opens the sign-in page.
codex mcp add your-site --url https://your-site.com/wp-json/cowboy-mcp/v1/endpoint - Gemini CLI and Opencode: one
mcp addcommand, then the app opens the sign-in page the first time it connects. - Cursor and VS Code: click Add to Cursor or Install in VS Code on the Connections tab, accept in the editor, and click Approve.
The Connections tab shows the exact command for your site, ready to copy. You don't have to swap in your own address or key. Config files are still there as a fallback, folded away under each command. It works on local development sites too: no public address or tunnel needed.
API keys haven't gone anywhere. For scripts, CI, and anything that can't show a sign-in page, generate a key on the Connections tab and send it in a header, as before.
Claude Code and Codex: no setting to switch on first
Apps that sign in for the first time have to register with your site, and Cowboy MCP only accepts new registrations while New connections is switched on. Claude Code and Codex now identify themselves with a Client ID Metadata Document, the newer way the MCP standard handles this, so they never register, and the switch doesn't apply to them. Run the command, click Approve, done.
For the other apps, copying the command or clicking the button on the Connections tab opens the 30-minute connection window and switches sign-in on for you, so there's nothing to set up first.
A tidier Connections tab
- Each setup panel leads with one command to copy and run. Config files and API keys are the collapsed fallback.
- The tab is shorter, and it confirms live when the app connects.
- The Desktop Connector setting is now called Browser sign-in, since it now covers every app, not only desktop ones.
- Custom access has Select all and Deselect all buttons, so a list of allowed tools no longer means dozens of clicks.
- The page header always shows whether Power mode is on or off. It turns red when Power mode is on, and one click takes you to its settings.
Also fixed
- Cursor sign-in is fixed.
- A server address with a trailing slash now connects.
- The Connection Doctor no longer shows warnings on local sites that don't apply to them.
- The plugin's own transients, the short-lived data it keeps for things like sign-in, are now off-limits to the option tools and WP-CLI.
Update
Update from your WordPress dashboard like any other plugin, or install it from WordPress.org. The full changelog is there too. Step-by-step setup for each app is in the connection guides: Claude Code, Codex, Gemini CLI, Cursor, Claude Desktop, Claude, and ChatGPT.