Wiele runs a remote MCP server. It exposes the CLI's remote commands as tools: organizations, workspaces, files, history, copies, merges, conflicts, access, retention and billing. Results carry the same data as the CLI prints with --json.
| Endpoint | https://api.wiele.io/mcp |
| Transport | Streamable HTTP, POST only, JSON responses, no sessions |
| Authentication | Authorization: Bearer TOKEN, where the token is a Wiele session |
| Capabilities | Tools only. No resources or prompts. |
What can connect
Any client that can send a fixed Authorization header: Claude Code, Codex, Cursor and others.
claude.ai and ChatGPT connectors can't connect yet. They need OAuth, and Wiele's MCP server only accepts a bearer token. In those apps, use the CLI through an agent that runs commands instead, such as Claude Code or Codex.
Get a token
The token is a Wiele session. Sign in to a separate session kept in a file, so you can revoke the MCP token without signing out the CLI:
mkdir -m 700 ~/.wiele-mcp
wiele login --credential-file ~/.wiele-mcp/session.json
export WIELE_MCP_TOKEN="$(jq -r .credential ~/.wiele-mcp/session.json)"
The configurations below read the token from WIELE_MCP_TOKEN, which keeps it out of config files where they allow it. Start the client from a shell where the variable is set.
A session lasts 7 days from its last refresh, and every MCP request refreshes it at most once a day. A token in regular use keeps working until you revoke it.
Claude Code
claude mcp add --transport http --scope user wiele https://api.wiele.io/mcp \
--header "Authorization: Bearer $WIELE_MCP_TOKEN"
The shell expands the variable, so ~/.claude.json stores the token itself. To keep it out of that file, add the server to a .mcp.json instead. Claude Code expands ${VAR} in headers when it starts:
{
"mcpServers": {
"wiele": {
"type": "http",
"url": "https://api.wiele.io/mcp",
"headers": { "Authorization": "Bearer ${WIELE_MCP_TOKEN}" }
}
}
}
Check it with claude mcp get wiele. Remove it with claude mcp remove wiele.
Codex
In ~/.codex/config.toml, or .codex/config.toml in a trusted project:
[mcp_servers.wiele]
url = "https://api.wiele.io/mcp"
bearer_token_env_var = "WIELE_MCP_TOKEN"
tool_timeout_sec = 150
codex mcp add wiele --url https://api.wiele.io/mcp --bearer-token-env-var WIELE_MCP_TOKEN writes the same entry without the timeout. Codex stops a tool call after 60 seconds by default, and some Wiele tools wait up to 120 seconds, so raise tool_timeout_sec or pass a smaller waitMs.
Cursor
In ~/.cursor/mcp.json, or .cursor/mcp.json in a project:
{
"mcpServers": {
"wiele": {
"url": "https://api.wiele.io/mcp",
"headers": { "Authorization": "Bearer ${env:WIELE_MCP_TOKEN}" }
}
}
}
Cursor reads ${env:NAME} from its own environment. If it started before you exported the variable, quit it and start it from that shell.
Other clients
Point the client at https://api.wiele.io/mcp and send Authorization: Bearer TOKEN on every request. The server supports MCP protocol versions 2025-03-26, 2025-06-18, 2025-11-25 and 2026-07-28. The server refuses requests from browsers, which send an Origin header.
Revoke a token
wiele auth logout --credential-file ~/.wiele-mcp/session.json
The next request with that token fails with 401. The CLI's own session keeps working. Remove the server from each client too.
The token has your account's full power
There are no scoped or read-only tokens yet. A client holding the token can do everything you can: read every workspace you see, push, merge, invite and remove members, change retention, prune versions and start billing changes.
- Keep the token out of shared files. Never commit a
.mcp.jsonorconfig.tomlthat contains it, and never paste it into a chat. - Use a separate session for MCP, as above, so revoking it affects nothing else.
- Turn on your client's confirmation prompts for tools that change data. Each tool says whether it reads, writes or removes data.
How tools behave
organizationis required on most tools. There's no default organization over MCP.workspacetakes an ID, slug or name, andpathalso acceptsWORKSPACE:/path.branchdefaults tomain.- Tools that change something take an optional
idempotencyKey(a UUIDv7). Without one the server generates a key and returns it in the result's_metaunderio.wiele/idempotencyKey. Call again with the same key to retry safely. - Tools that start server work take
waitMs: 30,000 by default, at most 120,000.0returns at once. A wait that runs out fails withOPERATION_PENDING; call again with the same key, or check withoperation_show. - Merge drafts travel as JSON.
conflict_listreturns adraft; pass it toconflict_showandconflict_resolve, then tobranch_merge_approveasapproval. - Failures come back as tool results with
isError: trueand{ error: { code, message, retryable, nextActions } }. The codes are the same as the CLI's; see error codes.
Limits
- Request bodies up to 1 MiB.
path_readreturns file content inline up to 1 MiB, and folder contents up to 768 KiB per page with 256 KiB per file.file_readreturns text inline up to 64 KiB. Larger files come back as a short-lived signed download URL.path_writechanges up to 100 paths, 512 KiB per file.conflict_showshows a text diff only when both sides are 64 KiB or less.
What stays in the CLI
Anything that needs your local disk: fetch, track, status, diff, push, pull, restore, checkout, branch switch, live, sync, daemon, skills install, doctor and sign-in. org logo set is CLI and web only.
Tools
The server lists these tools. We build this table from the server code.
| Tool | Kind | Description |
|---|---|---|
auth_status |
Read | Show the user, session expiry and username behind this connection's credential. Same data as wiele auth status --json. |
settings_list |
Read | List the signed-in user's account settings with their version. |
settings_get |
Read | Read one account setting (username or branch-name-template), or all settings when key is omitted. |
settings_set |
Write | Set username or branch-name-template. The server checks the current settings version, so a concurrent change fails instead of being overwritten. |
settings_reset |
Write | Reset username or branch-name-template to its default. |
onboarding_status |
Read | Show whether the user still has to create a first organization or accept pending invitations, and list those invitations. |
onboarding_complete |
Write | Finish onboarding with exactly one choice: name creates a default organization, invitationIds accepts pending invitations. |
org_list |
Read | List one page of the organizations the signed-in user belongs to. |
org_show |
Read | Show one organization by ID or slug, including the caller's role. |
org_create |
Write | Create an organization owned by the signed-in user. The slug defaults to the name in lowercase ASCII, so "Łódź Klienci" becomes lodz-klienci. |
org_leave |
Removes data or access | Remove the signed-in user's own membership. expectedVersion is the membership version from org_member_list. |
org_member_list |
Read | List one page of organization members with their roles and versions. |
org_member_set_role |
Write | Change an organization member's role to owner, admin or member. |
org_member_remove |
Removes data or access | Remove a member from the organization, revoking their access to its workspaces. |
org_invite |
Write | Invite an email address to the organization with an organization role and optional content grants (up to 20 resource or branch targets). |
org_invitation_list |
Read | List one page of the organization's invitations as an organization admin. |
org_invitation_show |
Read | Show one organization invitation with its state, targets and version. |
org_invitation_accept |
Write | Accept an invitation addressed to the signed-in user. Pending invitations are listed by onboarding_status. |
org_invitation_reject |
Removes data or access | Reject an invitation addressed to the signed-in user. |
org_invitation_revoke |
Removes data or access | Revoke a pending invitation as an organization admin. The invitee can no longer accept it. |
org_invitation_resend |
Write | Send a pending invitation's email again as an organization admin. |
org_rename |
Write | Rename the organization as an owner or admin. The slug stays the same. Logos are set in the web app or with wiele org logo set. |
org_logo_clear |
Write | Remove the organization's logo as an owner or admin. |
org_activity |
Read | List recent pushes, merges, copies and changes across the workspaces the caller can read, newest first. Owners and admins also see membership, access and retention changes. |
org_usage |
Read | Show files, size, open copies and daily pushes per workspace. Organization totals and stored version sizes are for owners and admins. |
billing_status |
Read | Show the organization's subscription state, plan, trial and period end, members against the plan's limit, and the retained storage that billing counts, every kept file version included. Fails with NOT_FOUND when the server does not bill. |
billing_checkout |
Write | Create a Stripe Checkout link for an organization owner or admin. A person opens it in a browser to add a card; the subscription starts after Stripe confirms it. New organizations get a 7-day trial. Never complete payment on the user's behalf. |
billing_plan |
Write | Move the organization's existing subscription to another plan, for an organization owner or admin. Stripe prorates the monthly price. Starter allows at most 3 members. |
billing_portal |
Write | Create a short-lived Stripe Customer Portal link where an organization owner or admin updates the card, views invoices or cancels. |
workspace_list |
Read | List one page of the organization's workspaces the caller can see. |
workspace_show |
Read | Show one workspace, including its initialization state and version. |
workspace_create |
Write | Create a workspace and wait until it is ready. The slug defaults to the name in lowercase ASCII. With waitMs 0 the result is the accepted provisioning state. |
workspace_retry |
Write | Resume a blocked workspace initialization and wait until it is ready. Exhausted Git sends allow observation only; exhausted provisioning receives five further attempts. |
workspace_archive |
Removes data or access | Archive a workspace as an organization admin. Members lose access to its files. |
workspace_visibility |
Write | Make a workspace public to every organization member, with read or write access, or private to people with a grant, as a workspace admin. |
workspace_usage |
Read | Show workspace storage use and original backup coverage as an organization admin. |
workspace_backup_show |
Read | Show the backup state of one stored original by content OID. |
workspace_backup_retry |
Write | Resume an original backup after its retry budget is exhausted. |
workspace_retention_show |
Read | List the workspace's version retention policies, for an organization owner or admin. With no policy every file version is kept. |
workspace_retention_set |
Write | Set how long past file versions are kept for a file, under a folder or in the whole workspace, for an organization owner or admin. A past version stays while it is one of the newest keepVersions versions of its file or was replaced less than keepDays ago; with both, either keeps it. Current files on every branch are never removed. With neither limit every version is kept, overriding a parent policy. A stricter setting starts after 7 days; the old one protects versions until then. Confirm with the user before setting a policy. |
workspace_retention_clear |
Write | Remove a file's, folder's or the workspace's retention policy so it follows its parent or the organization default again, for an organization owner or admin. Takes effect after 7 days. |
workspace_retention_explain |
Read | Show the retention rule that applies to a file, folder or the workspace, and whether it comes from that path, a parent, the workspace or the organization default. |
org_retention_show |
Read | Show the organization's default version retention, which applies wherever no workspace, folder or file policy is set. Null limits keep every version. |
org_retention_set |
Removes data or access | Set the organization's default version retention, for an organization owner or admin. A past version stays while it is one of the newest keepVersions versions of its file or was replaced less than keepDays ago; with both, either keeps it. Current files on every branch are never removed. With neither limit every version is kept, which is recommended. A stricter setting starts after 7 days, then past versions outside the limits in every workspace without its own policy are deleted for good. Confirm with the user first. |
workspace_retention_prune |
Write | Delete past file versions under a folder or the whole workspace now, for an organization owner or admin. A past version stays while it is one of the newest keepVersions versions of its file or was replaced less than keepDays ago; with both, either keeps it. Current files on every branch are never removed. Removes at most 100 versions per call; repeat while remaining is true. Deleted versions cannot be recovered: run with dryRun first and confirm with the user. |
file_stat |
Read | Show metadata for one file or folder on a branch: resource ID, kind, size, content OID and revision. |
file_list |
Read | List one page of the files and folders the caller can see inside a folder. |
file_entries |
Read | List where the caller can start browsing a workspace: the root when they can read it, otherwise the topmost folders and files shared with them, with their paths. |
file_read |
Read | Read one file at a pinned revision. Small text files come back inline (download.kind text), empty files as empty, anything else as a short-lived signed download URL. |
path_read |
Read | Read a file with its content, or a folder's entries depth first with their contents, at one revision. UTF-8 text comes back as text and other bytes as base64. A folder page that ends early returns nextCursor, pinned to the same revision. With since, a folder read returns only what changed after that revision and the paths it removed. |
path_write |
Write | Write and delete up to 100 paths in one revision. Every path needs a precondition in expected, or give baseRevisionSha or expectedHeadSha. A path that does not match refuses the whole write with WRITE_CONFLICT and its current hash. Returns the new revisionSha and each file's sha256. Retrying with the same idempotencyKey returns the original result. |
file_history |
Read | List the first-parent history of one resource on a branch, including deleted versions. Page with after. |
revision_show |
Read | Show one revision on a branch: when it was made, its parents and the changed paths. |
revision_diff |
Read | List the paths that changed between two revisions of a branch. |
branch_list |
Read | List one page of the workspace's branches the caller can see. Page with after. |
branch_show |
Read | Show one branch: head revision, scope, visibility, collaborators, version and policy epoch. |
branch_history |
Read | List the branch's revisions, newest first. Page with after. |
branch_compare |
Read | List the resources whose visible state differs between a branch and another branch (main by default), with before (target) and after (source) states. |
branch_merge_plan |
Read | Plan merging source into target (main by default): every changed entry, conflicts, and whether the merge can proceed. Use conflict_list to get an approvable draft. |
branch_merge_approve |
Write | Merge a branch using an approval draft from conflict_list or conflict_resolve, then wait for the merge to commit. The draft pins both heads and the plan digest, so a moved branch fails with HEAD_MOVED. |
branch_create |
Write | Create a branch from another branch (main by default), optionally scoped to one folder, and wait for it to commit. Without a name the server applies the user's branch-name template. |
branch_settings |
Write | Change a branch's visibility or default collaborator access. Omitted settings keep their values; omitted expectedVersion and expectedPolicyEpoch come from a fresh read. |
branch_archive |
Removes data or access | Archive a branch. It disappears from listings and can no longer be changed. |
branch_collaborator |
Removes data or access | Add a branch collaborator or change their role (read, write or admin). role remove takes the collaborator off the branch and removes their access. |
conflict_list |
Read | List the conflicts between a branch and its merge target (main by default). Returns a draft that pins both heads; pass it to conflict_show, conflict_resolve and finally branch_merge_approve. |
conflict_show |
Read | Show one conflict with its base, target and source sides and a target-to-source text diff. The diff is available only when both sides are small text files returned inline. |
conflict_export |
Read | Return the base, target and source originals of one conflict: inline text for small files, otherwise a short-lived signed download URL. |
conflict_resolve |
Read | Record a whole-file choice for one conflict in the draft: take source, target or delete. Nothing changes on the server; the result carries the updated draft and the conflicts that remain. |
operation_show |
Read | Show the state of a content operation such as a publication, branch creation or merge. |
operation_cancel |
Removes data or access | Cancel a content operation that has not committed yet. |
operation_incident |
Read | Inspect the recovery state of a blocked publication before requesting a fence. |
operation_fence |
Removes data or access | Request an audited recovery fence for a blocked publication. Positive Git observation, not this request, decides the result. |
upload_show |
Read | Show the verification state of an uploaded content candidate. |
upload_retry_verification |
Write | Resume verification of sealed upload bytes paused by its budget. Hash mismatches cannot be retried. |
access_show |
Read | Show the direct grants and policy epoch of one resource as a source admin. |
access_list |
Read | List the direct grants on a workspace path on main, as a source admin. |
access_explain |
Read | Explain a user's effective role on a path (default /) or on a branch, and every grant behind it. Give path or branch, not both. user is a user ID or member email and defaults to the caller. |
access_invite |
Write | Invite an email address to the organization as a member with one content role on up to 20 workspace paths. |
access_grant |
Write | Grant an organization member a content role (read, write or admin) on one resource. |
access_revoke |
Removes data or access | Remove a member's direct grant on one resource. |
version |
Read | Show this server's version and the API capabilities: protocol version, formats, features and limits. |
skills_list |
Read | List the agent skills bundled with Wiele. |
skills_print |
Read | Return the SKILL.md instructions of one bundled agent skill, such as wiele-conflicts. |
The four search tools, search_query, search_status, search_index and search_disable, are hidden while server-side search is off.