Use MCP Access to connect an approved MCP client to Tahr. Open the user menu, select Profile, then select MCP. Each connection is scoped to one organization, so verify the organization before you connect.
#Check access
If the page says access requires a grant, ask an administrator to grant access. Users with MCP management permission can use Administration -> MCP. If the organization has disabled MCP or no organization is active, follow the guidance shown in the app.
If your MCP client reports “Ask your administrator to enable MCP access.”, login succeeded but your account has no individual MCP access and the organization has not enabled access for everyone. This applies to OAuth and valid personal tokens. Ask your administrator to allow access; signing in again will not resolve it. Expired or revoked credentials must still be replaced or reauthorized.
#Organization-wide access
Administrators with MCP management permission can turn on Enable MCP for everyone in Administration -> MCP. This allows all active current and future members, including members previously disabled individually. Individual switches lock and show Enabled by organization while this setting is on.
Turning the setting off restores saved individual access settings. Members without individual access lose MCP access immediately; their credentials are suspended, not deleted. Turning it back on resumes valid, non-revoked credentials. Platform MCP restrictions and each member's role permissions still apply. Members must connect their own OAuth client or create a personal token.
#Connect a client
#OAuth
When OAuth is enabled, copy the endpoint from Profile -> MCP into your OAuth-capable client or Cloudflare MCP Portal. Start the client's sign-in flow, then select your organization. Your administrator must allow MCP access individually or for everyone first. The client handles token refresh automatically.
For Cloudflare MCP Portal, select OAuth for the upstream server and keep Require user auth enabled so each person connects with their own Tahr account.
#Personal token
- In Profile -> MCP, copy the endpoint shown for the active organization.
- Review the available tools so you understand what the client can access.
- Create a personal token. Add a recognizable label and select a 90, 180, or 365-day lifetime.
- Copy the token immediately. It is shown only once.
- Use the client configuration provided in Tahr. Store the token as a bearer credential in your client, without publishing it.
#Manage connected apps
Connected apps shows your OAuth connections for the current organization, their status, and last use. Disconnect blocks that connection in the current organization immediately, including refreshed tokens.
To reconnect a disconnected app, select Disconnect everywhere, confirm, then sign in again from your MCP client. This disconnects the app from all your Tahr connections, not only the current organization. If it can't complete, the app stays disconnected locally and you can try again.
#Manage tokens
The token list shows each token's status: active, suspended, expired, or revoked. Check its expiry date and last-used time before keeping it. The active-token limit is shown in the app.
Revoke a token you no longer need, suspect is exposed, or need to replace. Create a replacement token and update the client before revoking a token that is still in use.
#Keep tokens safe
Never share, commit, or log a token. Use environment variables or your MCP client's secret storage. Revoke a token immediately if it is exposed. After switching organizations, verify the active organization before using or creating a token.