Authentication
The MCP Server accepts Auth0-issued bearer tokens forhttps://api.checklyhq.com/mcp. Your MCP client completes the OAuth flow and sends the token with requests to the MCP endpoint.
The public MCP Server only supports OAuth clients that Checkly has approved in Auth0. Checkly rejects clients that attempt to use Dynamic Client Registration (DCR). See supported clients for setup details.
Checkly maps the token subject to a Checkly user, then loads that user’s account memberships and account context for tool calls.
OAuth permissions
Tools are filtered from
tools/list when the MCP session does not include the required permission. Tool calls are also rejected if the session lacks the required permission.
Account context
Most tools operate on one Checkly account. You can select a specific account in your prompt or pin an account in your MCP client configuration. See Use a specific account for setup examples.Role checks
Some tools require both an OAuth permission and a Checkly account role:Write-action safety
Some MCP tools create side effects:invite-account-membersends an invite email and is not idempotent.trigger-checksconsumes check-run execution quota.trigger-root-cause-analysisconsumes RCA invocation quota.create-status-page-incident,update-status-page-incident, andresolve-status-page-incidentcan notify subscribers and are not idempotent.- Environment variable write tools can create or replace account-level variables and secrets.
Secrets
MCP read tools never reveal Checkly secret values. Secret values are returned asnull.
When you create or update a secret through MCP, Checkly encrypts the value and does not echo it back in the tool response.