Browse guides

Operate

AI integrations

v1.2 authenticated private MCP and plugin setup for local desktop and coding assistants.

Guide type: Implementation reference

In this guide

Requires launcher 1.2.0 or later and a SuperUser account with CLI permission. Private downloads require authentication; Settings > Developer tools shows Not yet available when a release is missing.

Automatic hook platform support

Automatic hooks run on macOS and Linux only. On Windows they refuse to run, because they rely on POSIX file-ownership checks; the Windows CLI engine and MCP server are not affected.

Prepare the local engine

Follow Install the CLI: install the public launcher, check for version 1.2.0 or later, run magdox login, then magdox install. Check the local installation with magdox doctor before configuring your host.

Install authenticated private MCP and the plugin bundle

bashexample
# Requires product authorisation and compatible signed private MCP and plugin artifacts.
magdox mcp install

This command authenticates and downloads the signed private MCP server for your platform plus the portable plugin bundle. The catalog lists MCP separately from the engine; the plugin package retains any/any platform selectors. A successful download does not write host configuration or automatically enable any host. Engine provisioning remains magdox install.

Print configuration for one local client

Replace /absolute/path/to/repository with an existing absolute repository directory, and choose the client value below. The explicit --root is mandatory for both configuration and serving; there is no implicit current-directory or whole-machine scope. The examples use POSIX shell quoting; a Windows path such as 'C:\Repositories\app' can be used in PowerShell.

bashexample
# Replace the repository path before running.
magdox mcp config claude-desktop --root '/absolute/path/to/repository'

The command prints only a client configuration template: JSON for the listed clients except codex, which receives TOML. It writes no host files and copies no credentials. Review and manually merge the template into your host settings; no additional setup instructions are printed. Do not paste account credentials into host settings. Configuration templates are not proof of end-to-end host validation.

Print configuration for one local client
Local MCP clientClient valueEnd-to-end validation
Claude Desktopclaude-desktopNot validated; configuration template
Claude Codeclaude-codeTested end to end
CursorcursorNot validated; configuration template
VS Code (GitHub Copilot)vscodeNot validated; configuration template
WindsurfwindsurfNot validated; configuration template
Gemini CLIgeminiNot validated; configuration template
Codex CLIcodexNot validated; configuration template
ClineclineNot validated; configuration template
Other local stdio MCP clientgenericNot validated; configuration template

Claude Code is the only host tested end to end. The other values print configuration templates that follow each host's documented format; they have not been validated end to end, so confirm the server loads and a scan runs in your host.

Local stdio serving

bashexample
# Replace the repository path before running.
magdox mcp serve --root '/absolute/path/to/repository'

The host normally starts the server process. This direct command uses stdio by default and requires the same explicit repository-root boundary. Keep MCP local: do not use ngrok, public tunnels or an unauthenticated network endpoint. Remote web-client setup is not offered by this workflow.

Compatibility: host hooks and workflows

The integrations commands configure host hooks and workflows separately from desktop MCP. Only the Claude Code hook integration has been tested end to end; other host setups remain experimental.

Download and view setup

Choose one host or workflow below. This example selects Claude Code; replace claude-code with the exact host value for your workflow.

bashexample
# Requires product authorisation and a compatible signed private integration bundle.
magdox integrations install claude-code

The command authenticates, downloads the signed private integration bundle and prints host-specific remaining setup. Follow the instructions in your terminal to finish. Downloading the bundle does not automatically enable every host, and a successful download is not an end-to-end integration test. Review the printed setup for your installed host version.

Download and view setup
AI host or workflowCommandValidation status
Claude Codemagdox integrations install claude-codeOnly integration tested end to end
Cursormagdox integrations install cursorExperimental
Codexmagdox integrations install codexExperimental
Gemini CLImagdox integrations install geminiExperimental
GitHub Copilotmagdox integrations install copilotExperimental
Windsurfmagdox integrations install windsurfExperimental
OpenCodemagdox integrations install opencodeExperimental
pre-commitmagdox integrations install pre-commitExperimental

Only the Claude Code integration has been tested end to end. This does not establish that every feature or host version works. Other hosts and the pre-commit workflow remain experimental, and Windows hooks are unsupported.

Check locally, then verify in your host

bashexample
magdox doctor

magdox doctor checks local installation and authorisation state only. Manually merge the MCP template or complete the separate hook setup instructions, then verify the integration in the selected host. Sessions and devices shows server-recorded sign-ins only; it cannot prove that local files are installed, that the host loaded them or that a scan ran.

Source and findings

Source analysis stays local to the scanner. Findings are returned to the assistant and are subject to your AI provider's data policy. Source you share directly with that assistant is also subject to its policy. Local scanning does not make the assistant's conversation or findings private from its provider. Optional CLI AI review is a separate opt-in feature described in AI review with your own model.

Offline use

Expiring licences work offline for up to 7 days on Team, 30 days on Business and 90 days on Enterprise, bounded by licence expiry and the applicable signed grant, and never past the end of a trial, a cancelled subscription's last paid period or the grace after a failed payment. When an organisation's plan lapses, the platform issues no new leases or rule keys: the CLI stops loading rules when its current lease ends, and deletes its cached rule leases as soon as the platform tells it the plan has ended or access was withdrawn. Cache the authorised engine, rules and required data before disconnecting. New MCP and integration downloads require connectivity; an installed bundle does not extend the grant. For a manual air-gapped engine import, save the engine artifact and its signed manifest. The launcher does not expose offline import for MCP or integration bundles. Perpetual air-gapped or internal use requires an explicit perpetual grant and arranged provisioning. A remote AI assistant may still need a network connection even when the scanner can run offline.