Transport and sign-in
The MCP server speaks the Streamable HTTP transport at https://mcptask.online/mcp. A client config names it with "type" set to "http" and sends the user's MCPTASK_TOKEN in an Authorization Bearer header. Claude Cowork and claude.ai sign in over OAuth 2.0 instead.
- The token is a JWT signed with HS256. It carries the permissions of its user — there are no extra scopes.
- The MCP server is rate limited: 60 requests a minute per token, plus an hourly cap per account set by the plan (REST API → Rate limits below).