MCP server
When a check fails, your agent can read the evidence instead of handing you a dashboard link. releasetwin-mcp is a local stdio MCP server over the read-only programmatic API. Team tier and above.
Try it first, without a token
The live example organization is readable by anyone, so the server works against it with no token at all. Point your agent at its full project project and ask it why the last run failed — nothing to sign up for, nothing to issue:
claude mcp add releasetwin-demo \
--env RELEASETWIN_API_URL=https://api.releasetwin.com \
--env RELEASETWIN_PROJECT_ID=2c48e2cf-4f59-4765-9299-74a83f5d3a57 \
-- npx -y releasetwin-mcpWithout a token every tool reads that one project; any other id comes back “not found”. To read your own project, continue below.
1. Issue a read-only token
On a project's Settings page, click Issue read-only API token. It is shown once, so store it before you close the dialog. The same token type the programmatic API uses: it can never upload a report, and the ingest API rejects it outright.
You also need the project's id, which is in the URL of its dashboard page. A read-only token is issued for one project and the server cannot work out which from the token alone, so it is configured explicitly.
2. Point your agent at it
Nothing to install — npx fetches the server on first run. For Claude Code, put this in .mcp.json at the root of your repository, so it is shared with everyone working on it:
{
"mcpServers": {
"releasetwin": {
"command": "npx",
"args": ["-y", "releasetwin-mcp"],
"env": {
"RELEASETWIN_API_URL": "https://api.releasetwin.com",
"RELEASETWIN_API_TOKEN": "<your read-only token>",
"RELEASETWIN_PROJECT_ID": "<your project id>"
}
}
}
}Or add it from the command line, which writes the same configuration for you:
claude mcp add releasetwin \
--env RELEASETWIN_API_URL=https://api.releasetwin.com \
--env RELEASETWIN_API_TOKEN=$RELEASETWIN_API_TOKEN \
--env RELEASETWIN_PROJECT_ID=$RELEASETWIN_PROJECT_ID \
-- npx -y releasetwin-mcpCursor uses the same shape, in .cursor/mcp.json for one project or ~/.cursor/mcp.json for all of them.
Codex keeps its configuration in TOML, at ~/.codex/config.toml:
[mcp_servers.releasetwin]
command = "npx"
args = ["-y", "releasetwin-mcp"]
env = { RELEASETWIN_API_URL = "https://api.releasetwin.com", RELEASETWIN_API_TOKEN = "<your read-only token>", RELEASETWIN_PROJECT_ID = "<your project id>" }Restart the agent afterwards, then ask it something that needs the data — “why did the last checkout run fail?” is a good first test.
3. What your agent can read
| Tool | Reads | Also needs |
|---|---|---|
list_reports | Run history, newest first, with each case's flakiness state | — |
get_report | One report by id | — |
get_evidence | A report's redacted evidence, with screenshots as images | — |
get_release_rollup | A release's readiness headline and per-case standing | releaseRollup |
diff_releases | What regressed or recovered between two releases | releaseRollup |
check_flag_gate | Recorded flag-proof merge-gate verdicts | flagProofMergeGate |
get_flag_blast_radius | The cases in this project that ride a flag key | flagBlastRadiusView |
list_flaky_cases | Cases whose results are not usable as evidence | trendAnalytics |
Every tool needs the programmaticApiAccess entitlement that read-only tokens come with. The ones naming a second entitlement need both — access to the API is not access to every feature in it, so a plan without release rollups cannot read them here either. A tool whose entitlement is missing returns an error naming it, never an empty result your agent would report back as “nothing to see”.
get_evidencereturns each screenshot as an image your agent can actually look at, alongside the redacted document.get_flag_blast_radiusanswers for your token's own project, not the whole organization. A read-only token is scoped to one project, so it cannot surface a sibling project's cases — the dashboard is where you see the organization-wide view.- The resource
releasetwin://project/{projectId}/latest-rungives your agent the most recent run without it having to choose a tool.
Everything is read-only
There is no tool here that triggers a run, approves a result, or changes a report. Runs happen in your CI, where they belong; this server exists so an agent can read the evidence and explain a failure. Requests it makes are the same paged, rate-limited, read-only requests the programmatic API serves to any other client.
About the token
- It sits in your agent host's config file in plaintext. That is how every stdio MCP server is configured. Keep it out of commits if the file is shared — reference an environment variable instead of pasting the value.
- It can only read. The ingest API rejects it, so it cannot upload, change, or delete anything.
- It reaches exactly one project. Any other project's id returns “not found” — indistinguishable from an id that does not exist, so it cannot be used to probe for other projects.
- Revoking it takes effect immediately. Revoke it on the project's Settings page; so does losing the entitlement, which stops the token working without your having to revoke it. See Security & credentials.
- The server never writes the token into a tool result, a resource, or an error message, even when the API rejects it.