Skip to main content
Portfobit uses a remote Model Context Protocol (MCP) server. Codex, Claude Code, Cursor, OpenClaw, and Hermes connect with browser-based OAuth, so you do not need to create or paste an API key first.
During OAuth authorization, review the requested scopes and keep write scopes off unless they are needed. activity:write starts bounded history imports; trade:write and transfer:write authorize protected actions subject to additional safeguards. Direct OpenAPI integrations should use only the scopes their endpoints require.

Choose a setup method

Start from Plugin or MCP Server Setup on the Portfobit homepage. Codex and Claude Code offer plugin installation first; the manual MCP options support other clients and deployment environments. Paste this into Codex or Claude Code, replacing the client name with the one you use:
For Claude Code, say Claude Code plugin marketplace in place of Codex plugin marketplace. The homepage’s client tab provides the exact prompt for each agent. The existing manual Remote MCP method remains below.

Manual Remote MCP setup with OAuth

Choose your client tab on the Portfobit homepage. Add the MCP URL without an Authorization header, run the login command, and choose the scopes you want to grant. For Codex:
The other verified clients use the same browser authorization flow. OpenClaw and Hermes also have a Bearer fallback for remote or headless deployments where the loopback callback cannot reach the running Agent. Do not add a static Authorization header to an OAuth connection; clients commonly prioritize that header instead of starting OAuth.
For OpenClaw or Hermes on a VPS, container, or unattended gateway, use the dedicated guide’s Headless / Bearer configuration. Give that deployment its own least-privilege Developer API Key so it can be revoked independently. Do not expose the key in shell history, source control, logs, or chat.

API key compatibility

Developer API keys remain available for direct Open API integrations, CI, scripts, service accounts, and MCP clients that do not support OAuth. For clients that support the common mcpServers JSON shape, use:
<PORTFOBIT_API_KEY> is a placeholder to replace with a scoped Developer API Key, not an environment-variable reference. If your client supports secret substitution, use its own syntax instead. Never commit a configuration containing the key, paste the secret into a chat prompt, or use a CEX credential here.

Setup guides

For unverified Claude Desktop interoperability, see the separate Claude Desktop note. After setup, ask your agent: “Use portfobit to list the account connectors I can connect.” A successful response proves the MCP server can authenticate and reach Portfobit.