Headless, CI and scripts
Connect a script or a CI job to looot with a header token, no browser required.
CI runners and scripts can’t open a browser, so they sign in with a token in the header.
Create the token
Go to Settings, Agent tokens, on looot.ai and create a token with only the scopes the job needs and a short expiry. Never commit it.
Store it as a secret
Put the token in your CI provider’s secret store, as LOOOT_TOKEN. Then point any MCP client at
the server URL with the header:
Authorization: Bearer ${LOOOT_TOKEN}
Example: GitHub Actions with Claude Code
- run: |
claude mcp add --transport http looot https://api.looot.ai/mcp \
--header "Authorization: Bearer $LOOOT_TOKEN"
env:
LOOOT_TOKEN: ${{ secrets.LOOOT_TOKEN }}
Each client page under Connect has its own header fallback config: see Claude Code, Codex, Cursor, VS Code, Gemini CLI, Windsurf, Grok and mcp-remote.
Check it works
curl -s https://api.looot.ai/mcp -X POST \
-H "Authorization: Bearer $LOOOT_TOKEN" \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
A working token returns the tool list. See Troubleshooting for what a 401 or a missing tool means.