Skip to main content
The MCP server accepts two kinds of credentials. The one you pick decides what the assistant can see. In Claude Code, Codex, Cursor, Gemini CLI, VS Code, and Windsurf, leave the key out of the config to sign in with OAuth. Put the key in to use the API key. Both expose the same tools.

OAuth, scoped to you

The assistant acts as the person who approved the connection. Lists and searches show only what that person can see. A meeting or booking they cannot open is refused. Use OAuth when a person drives the assistant. For the steps, see Connect agent.

What you approve

NeetoCal 'Authorize access' screen showing the workspace and signed-in email, a 'What this connection can do' list with Read and Stay connected always granted and Create and update and Delete as tickable boxes, a 'Workspaces to connect' list, and Cancel and Authorize buttons

The approval screen, with the scope picker and the workspace list.

If you leave a scope unticked, a tool that needs it is refused with a message that names the scope. For example, a read-only connection can list bookings but cannot book, reschedule, or cancel. One OAuth connection can reach several workspaces. Name the workspace in your prompt, or ask the assistant to list the workspaces it can reach. Every tool takes an optional workspace argument for this.

API key, scoped to the workspace

An API key is not tied to a person. Every tool call reaches the whole workspace, and role checks do not run. Use a key for automation that must see every booking. Do not use one on a machine where the person should see only their own bookings. The key is the same one the REST API uses. Put it in the server entry of the assistant’s config file:
For the full config of each client, see Connect agent. Learn how to generate your API key.
A key belongs to one workspace. To reach two workspaces, add the server twice, with a different key and a different server name in each entry.
An API key gives access to every meeting and booking in the workspace. Treat it like a password: keep it out of shared config files and commits, and revoke it if it leaks.

How the three interfaces authenticate