Subtext MCP server
- Endpoint
-
https://api.fullstory.com/mcp/subtext - Transport
- streamable-http
- Docs
- https://subtext.fullstory.com/docs/install/manual
OAuth · resolves from well-known metadata Point your MCP client at the server URL and approve access in the browser. The server supports OAuth Dynamic Client Registration (RFC 7591), so the client registers itself automatically — no developer-portal app, client_id, or client_secret to create.
OAuth · resolves from well-known metadata Sign in with your Subtext account. No manual configuration is needed for agents that support MCP OAuth discovery: https://api.fullstory.com/mcp/subtext answers an unauthenticated request with 401 and WWW-Authenticate: Bearer resource_metadata="https://api.fullstory.com/.well-known/oauth-protected-resource/mcp/subtext", which resolves to the authorization server https://auth.fullstory.com (RFC 9728).
The setup wizard runs the same flow locally: authorization code with PKCE, redirecting to an ephemeral 127.0.0.1 callback port, opening your browser to complete sign-in.
Scopes: sessions:read, settings.privacy:read, settings.privacy.element_block:write, settings.privacy.url:write.
Subtext is free to start.
Authorization: Bearer <credential> Create a key under Settings > API Keys in the Subtext app, then use it in place of the browser sign-in.
For the MCP server, send it as an Authorization: Bearer <key> header.
For the setup wizard, prefer the SUBTEXT_API_KEY environment variable over the --api-key flag. A key passed as a flag lands in your shell history and is visible to other local users through the process list.
Keep the key private and out of source control. On a shared machine or in CI, inject it from a secrets manager rather than writing it into a config file.