During OAuth authorization, review the requested scopes and keep write scopes off unless they are needed.
activity:write starts bounded history imports; trade:write and transfer:write authorize protected actions subject to additional safeguards. Direct OpenAPI integrations should use only the scopes their endpoints require.Choose a setup method
Start from Plugin or MCP Server Setup on the Portfobit homepage. Codex and Claude Code offer plugin installation first; the manual MCP options support other clients and deployment environments.Recommended for Codex and Claude Code: ask your agent to install the plugin
Paste this into Codex or Claude Code, replacing the client name with the one you use:Claude Code plugin marketplace in place of Codex plugin marketplace. The homepage’s client tab provides the exact prompt for each agent. The existing manual Remote MCP method remains below.
Manual Remote MCP setup with OAuth
Choose your client tab on the Portfobit homepage. Add the MCP URL without anAuthorization header, run the login command, and choose the scopes you want to grant.
For Codex:
Do not add a static
Authorization header to an OAuth connection; clients commonly prioritize that header instead of starting OAuth.
API key compatibility
Developer API keys remain available for direct Open API integrations, CI, scripts, service accounts, and MCP clients that do not support OAuth. For clients that support the commonmcpServers JSON shape, use:
<PORTFOBIT_API_KEY> is a placeholder to replace with a scoped Developer API Key, not an environment-variable reference. If your client supports secret substitution, use its own syntax instead. Never commit a configuration containing the key, paste the secret into a chat prompt, or use a CEX credential here.