OAuth
The manifests ship a URL and nothing else. Accounts are RapidReview accounts (email/password or Google).What the grant reaches
Every rotation inherits the grant. Membership is the authorization boundary — you only ever see projects you’re a member of. Members: Configure auth → Project members.
Remote machines over SSH
Consent redirects to a loopback URL on the machine running the client — Kilo Code and OpenCode listen on127.0.0.1:19876 during mcp auth merv. If that machine is a VM and the browser is your laptop, the redirect lands on the laptop and the client times out after five minutes.
On a remote machine over SSH, connect with
ssh -L 19876:127.0.0.1:19876 user@host first. The browser sign-in callback goes to 127.0.0.1:19876, and the forward is what lets it reach the client running on the remote host.ssh can’t bind 19876, another sign-in on the laptop holds it. Same technique for any client with a loopback redirect.
Project keys
Mint one only when there is no browser and no way to forward the callback port: scripted Auto-run installs and CI, containers, a client without MCP OAuth (OpenHands headless), directcurl.
Settings → MCP keys in the project → create → choose All my projects unless you want confinement → expose as MERV_MCP_KEY. Treat it as a password; never in shell history, logs, or committed files — native clients don’t need one, and the manifests are URL-only on purpose. merv-client env prints the header-based MCP snippet for a headless client.