> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ocean.security/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect other MCP clients

> Add the Ocean Security MCP server to any client that speaks MCP over streamable HTTP.

## Overview

Ocean doesn't need to be listed in a client's marketplace, directory, or app store to work —
any client that speaks MCP over **streamable HTTP** can connect. This guide covers the
generic setup; see the per-client guides in the sidebar for a walkthrough tailored to a
specific tool.

For connection details, authentication, and the full tool catalog, see the
[MCP Server Overview](/api-reference/mcp/overview).

## What you need

| Setting | Value |
| - | - |
| **Endpoint** | `https://api.ocean.security/mcp` |
| **Transport** | Streamable HTTP (`http`) |
| **Authentication** | OAuth 2.1 (if the client supports it) or an `X-Api-Key` header |

## Generic configuration

Most clients use some variant of this shape — the key names differ (`url`, `httpUrl`,
`serverUrl`), but the fields are the same. Check your client's docs for its exact schema.

```json theme={null}
{
  "mcpServers": {
    "ocean": {
      "type": "http",
      "url": "https://api.ocean.security/mcp"
    }
  }
}
```

If your client supports OAuth for remote servers, add the entry with no credential and let it
run the sign-in flow the first time it connects. If it doesn't — or you need the allow/deny
**write** tools, which OAuth can't reach — add an `X-Api-Key` header instead:

```json theme={null}
{
  "mcpServers": {
    "ocean": {
      "type": "http",
      "url": "https://api.ocean.security/mcp",
      "headers": {
        "X-Api-Key": "YOUR_API_KEY"
      }
    }
  }
}
```

<Warning>
  Don't commit a real API key to a shared config file. Reference an environment variable
  instead — `"X-Api-Key": "${OCEAN_API_KEY}"` — where your client supports it.
</Warning>

## Verify the connection

Use the [MCP inspector](https://github.com/modelcontextprotocol/inspector) to check the
endpoint independently of any client:

```bash theme={null}
npx @modelcontextprotocol/inspector
```

In the inspector's UI, select **Streamable HTTP**, enter
`https://api.ocean.security/mcp`, connect, and confirm Ocean's tools appear under
**Tools → List Tools**.

## Troubleshooting

See the [overview troubleshooting](/api-reference/mcp/overview#troubleshooting) — it covers
the same failure modes regardless of client.
