Quickstart: your first MCP approval

flowifai sits between your AI agent and local MCP tools, asks a human before high-impact calls run, and leaves the real service credentials on your machine. The setup wizard can discover and protect several existing Claude Code or Cursor MCP servers in one run.

Commands on this page target https://app.staging.flowif.ai while the production application remains behind its launch gate.

1. Install the tools

Install the CLI, broker, and wrapper on the machine that runs your MCP tools:

curl -fsSL https://flowif.ai/install.sh | sh

Full installer details, update commands, and troubleshooting live in the install guide.

2. Preview discovery

Run this from the project whose project-scoped MCP entries you want to discover:

flowifai setup --dry-run

Dry run reads supported Claude Code and Cursor configuration and prints a redacted plan. It does not run an MCP server, open a browser, make a network request, or write a file.

3. Protect your MCP servers

Start the wizard:

flowifai setup

Choose numbers, a comma-separated list, a range such as 1,3-5, or all. Setup inspects the selected servers, opens browser authentication, creates a separate protected profile process for each distinct MCP, verifies every broker, and only then updates the client entries. See one-shot MCP setup for supported scopes, the environment boundary, accessible terminal behavior, and recovery.

4. Verify the setup

The setup result prints profile IDs. Verify one or all of them:

flowifai status --all
flowifai doctor --all --strict

Doctor exits nonzero if a selected profile is unhealthy. It does not prove end-to-end approval execution by itself.

5. Gate a tool and approve it

Open Policies, allow safe tools, and gate risky ones with a policy rule (see the policy reference). Gated calls appear in the inbox and approval notifications.

When a gated call fires, the agent’s tool call pauses as pending, you approve or deny it in the console, and the call completes on retry. In supported MCP clients the approval link is delivered protocol-natively, right in the client (see protocol-native approvals).

Common first-run questions

What if my client is not supported by setup?

The wizard currently modifies Claude Code user, project, and local scopes, and Cursor user and project scopes. Other clients are independently gated. Follow the manual setup path until your client and scope are explicitly listed as supported.

Do my MCP server’s credentials go to the flowifai cloud?

No. Credentials configured in your local MCP server stay on the tools host with the broker. The cloud backend stores policy, approval decisions, and audit records — never your downstream service credentials. Details are in the security model.

View this page as markdown · All docs as one file