Connect MCP
Connecting your agent to Tracecat Cloud automatically creates an account for you. You can also sign up manually via https://platform.tracecat.com. If you are self-hosted, replacehttps://platform.tracecat.com with your
PUBLIC_APP_URL (e.g. http://localhost or https://tracecat.example.com).
Authentication uses a built-in OIDC provider—your agent is redirected to sign in
through the browser on first connection. For clients or environments that cannot
complete a browser sign-in, authenticate with a
personal access token (PAT) instead.
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Cursor
Sign in with OAuth:Or authenticate with a personal access token (PAT).
Set
TRACECAT_MCP_PAT in your environment and reference it with single
quotes so the variable (not the token) is written to the saved config:Self-host
Choose a deployment method:- Docker Compose: Run every service on a single host. This is the fastest way to self-host.
- AWS ECS Fargate: Deploy to your own AWS account with Terraform.
- Kubernetes: Install the Helm chart on EKS, GKE, or any conformant cluster.
- Air-gapped deployment: Run on Kubernetes with no runtime internet access.
Docker Compose quickstart
Follow the full Docker Compose guide or run the commands below.First login
Set the first superadmin’s email before anyone signs in. Until it is set, nobody can register, and the first account must match it. It takes one case-sensitive email address, so use the exact casing your identity provider sends.- Basic auth: sign up with that email, then log in.
- SSO: log in through your identity provider. Tracecat creates the account on first login.
Next steps
- See Environment variables to configure your deployment.
- See TLS and certificates to serve Tracecat over HTTPS.
- See User management to invite your team.
- See SAML SSO or OIDC to sign in through your identity provider.