---
title: Headless, CI and scripts
description: Connect a script or a CI job to looot with a header token, no browser required.
sidebar:
  label: Headless and CI
---

CI runners and scripts can't open a browser, so they sign in with a token in the header.

## Create the token

Go to Settings, **Agent tokens**, on looot.ai and create a token with only the scopes the job
needs and a short expiry. Never commit it.

## Store it as a secret

Put the token in your CI provider's secret store, as `LOOOT_TOKEN`. Then point any MCP client at
the server URL with the header:

```txt
Authorization: Bearer ${LOOOT_TOKEN}
```

## Example: GitHub Actions with Claude Code

```yaml
- run: |
    claude mcp add --transport http looot https://api.looot.ai/mcp \
      --header "Authorization: Bearer $LOOOT_TOKEN"
  env:
    LOOOT_TOKEN: ${{ secrets.LOOOT_TOKEN }}
```

Each client page under [Connect](/connect) has its own header fallback config: see
[Claude Code](/connect/claude-code), [Codex](/connect/codex), [Cursor](/connect/cursor),
[VS Code](/connect/vscode), [Gemini CLI](/connect/gemini-cli), [Windsurf](/connect/windsurf),
[Grok](/connect/grok) and [mcp-remote](/connect/mcp-remote).

## Check it works

```bash
curl -s https://api.looot.ai/mcp -X POST \
  -H "Authorization: Bearer $LOOOT_TOKEN" \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
```

A working token returns the tool list. See [Troubleshooting](/connect/troubleshooting) for what a
401 or a missing tool means.

<Related />
