MCP server

When a check fails, your agent can read the evidence instead of handing you a dashboard link. releasetwin-mcp is a local stdio MCP server over the read-only programmatic API. Team tier and above.

Try it first, without a token

The live example organization is readable by anyone, so the server works against it with no token at all. Point your agent at its full project project and ask it why the last run failed — nothing to sign up for, nothing to issue:

Claude Code CLI — no token
claude mcp add releasetwin-demo \
  --env RELEASETWIN_API_URL=https://api.releasetwin.com \
  --env RELEASETWIN_PROJECT_ID=2c48e2cf-4f59-4765-9299-74a83f5d3a57 \
  -- npx -y releasetwin-mcp

Without a token every tool reads that one project; any other id comes back “not found”. To read your own project, continue below.

1. Issue a read-only token

On a project's Settings page, click Issue read-only API token. It is shown once, so store it before you close the dialog. The same token type the programmatic API uses: it can never upload a report, and the ingest API rejects it outright.

You also need the project's id, which is in the URL of its dashboard page. A read-only token is issued for one project and the server cannot work out which from the token alone, so it is configured explicitly.

2. Point your agent at it

Nothing to install — npx fetches the server on first run. For Claude Code, put this in .mcp.json at the root of your repository, so it is shared with everyone working on it:

.mcp.json
{
  "mcpServers": {
    "releasetwin": {
      "command": "npx",
      "args": ["-y", "releasetwin-mcp"],
      "env": {
        "RELEASETWIN_API_URL": "https://api.releasetwin.com",
        "RELEASETWIN_API_TOKEN": "<your read-only token>",
        "RELEASETWIN_PROJECT_ID": "<your project id>"
      }
    }
  }
}

Or add it from the command line, which writes the same configuration for you:

Claude Code CLI
claude mcp add releasetwin \
  --env RELEASETWIN_API_URL=https://api.releasetwin.com \
  --env RELEASETWIN_API_TOKEN=$RELEASETWIN_API_TOKEN \
  --env RELEASETWIN_PROJECT_ID=$RELEASETWIN_PROJECT_ID \
  -- npx -y releasetwin-mcp

Cursor uses the same shape, in .cursor/mcp.json for one project or ~/.cursor/mcp.json for all of them.

Codex keeps its configuration in TOML, at ~/.codex/config.toml:

~/.codex/config.toml
[mcp_servers.releasetwin]
command = "npx"
args = ["-y", "releasetwin-mcp"]
env = { RELEASETWIN_API_URL = "https://api.releasetwin.com", RELEASETWIN_API_TOKEN = "<your read-only token>", RELEASETWIN_PROJECT_ID = "<your project id>" }

Restart the agent afterwards, then ask it something that needs the data — “why did the last checkout run fail?” is a good first test.

3. What your agent can read

ToolReadsAlso needs
list_reportsRun history, newest first, with each case's flakiness state—
get_reportOne report by id—
get_evidenceA report's redacted evidence, with screenshots as images—
get_release_rollupA release's readiness headline and per-case standingreleaseRollup
diff_releasesWhat regressed or recovered between two releasesreleaseRollup
check_flag_gateRecorded flag-proof merge-gate verdictsflagProofMergeGate
get_flag_blast_radiusThe cases in this project that ride a flag keyflagBlastRadiusView
list_flaky_casesCases whose results are not usable as evidencetrendAnalytics

Every tool needs the programmaticApiAccess entitlement that read-only tokens come with. The ones naming a second entitlement need both — access to the API is not access to every feature in it, so a plan without release rollups cannot read them here either. A tool whose entitlement is missing returns an error naming it, never an empty result your agent would report back as “nothing to see”.

  • get_evidence returns each screenshot as an image your agent can actually look at, alongside the redacted document.
  • get_flag_blast_radius answers for your token's own project, not the whole organization. A read-only token is scoped to one project, so it cannot surface a sibling project's cases — the dashboard is where you see the organization-wide view.
  • The resource releasetwin://project/{projectId}/latest-run gives your agent the most recent run without it having to choose a tool.

Everything is read-only

There is no tool here that triggers a run, approves a result, or changes a report. Runs happen in your CI, where they belong; this server exists so an agent can read the evidence and explain a failure. Requests it makes are the same paged, rate-limited, read-only requests the programmatic API serves to any other client.

About the token

  • It sits in your agent host's config file in plaintext. That is how every stdio MCP server is configured. Keep it out of commits if the file is shared — reference an environment variable instead of pasting the value.
  • It can only read. The ingest API rejects it, so it cannot upload, change, or delete anything.
  • It reaches exactly one project. Any other project's id returns “not found” — indistinguishable from an id that does not exist, so it cannot be used to probe for other projects.
  • Revoking it takes effect immediately. Revoke it on the project's Settings page; so does losing the entitlement, which stops the token working without your having to revoke it. See Security & credentials.
  • The server never writes the token into a tool result, a resource, or an error message, even when the API rejects it.