Linear MCP server, with a policy gate.
Let agents file and update Linear issues without scattering API keys. Gentkey fronts the official Linear MCP server with one OAuth-protected URL, explicit write grants, and a per-agent audit trail.
https://app.gentkey.com/mcpclaude.ai (web & mobile) · Claude Code · Cursor · any MCP clientWhat’s free, what needs a grant.
Reads: Linear's tools ship write-gated until a curated read set lands — Gentkey doesn't take a vendor's word for what's read-only.
Writes: Grant mcp-linear.write and the connector opens — one switch to turn an agent's Linear access on or off, with an optional max-writes-per-hour bound.
Gentkey proxies the official Linear MCP server (https://mcp.linear.app/mcp) — you get the vendor’s own tools, with custody, gating, and audit added in front.
| Grant | What it governs |
|---|---|
mcp-linear.write | Every tool the official Linear server exposes — issues, projects, cycles, and reads too, until a curated read set lands |
Connect once, use everywhere.
Sign in at gentkey.com, add Linear (oauth), then point each client at your endpoint. Every client completes a standard OAuth flow and lands in your Gentkey — your connections, nobody else’s.
claude.ai (web & mobile)
- Settings → Connectors
- Add custom connector
- Paste
https://app.gentkey.com/mcpand finish the OAuth prompt
Claude Code
claude mcp add --transport http \
gentkey https://app.gentkey.com/mcpCursor
// .cursor/mcp.json
{
"mcpServers": {
"gentkey": { "url": "https://app.gentkey.com/mcp" }
}
}Things agents do with Linear here.
- What's assigned to me in the current cycle?
- File a bug: checkout button unresponsive on Safari, priority high.
- Move all in-review issues in the Mobile project to done.
- Which issues have been open longest in the backlog?
Custody, gating, and audit — built in.
The model never sees a credential
Your Linear token is encrypted at rest and injected server-side at call time. Your stored credential never enters a context window.
Writes need a grant
Anything that changes state needs a capability you granted explicitly — revoke it and the next call is denied.
A trail you can act on
Every decision is attributed to the agent that made it — allowed, denied, or denied by constraint.
Fair questions.
Why gate reads on an issue tracker?
Because Gentkey only marks tools read-free after curating them, and Linear's set isn't curated yet. Until then one grant covers the connector; when curation lands, reads go free and writes stay gated — the same path RevenueCat and Superwall already took.
What happens when an agent calls a Linear write tool it hasn't been granted?
The call is denied at the gateway — nothing reaches Linear — and the denial is recorded in the audit log along with the grant that would have authorized it, so you can decide deliberately instead of finding out later.
Where are my credentials stored?
Encrypted at rest (AES-256-GCM) on Gentkey's server and injected server-side at call time. No credential you store with Gentkey ever enters a model's context window or an agent's config file.
Can I use this from claude.ai's free plan?
Yes — and it's the strongest case for a gateway: free claude.ai accounts currently get a single custom connector, so pointing that one slot at Gentkey puts every connector you've linked behind it.
How do I revoke an agent's access?
Revoke the grant (the next write is denied) or revoke the agent's tokens entirely in one click. Other agents and their grants are untouched — no shared key to rotate.
Is Gentkey affiliated with Linear?
No. Gentkey is an independent MCP gateway. Trademarks belong to their owners; where an official Linear MCP server exists, Gentkey proxies it and adds custody, gating, and audit on top.
Often connected together.
Cut Linear a smaller key.
Sign in, connect Linear, and grant your first scoped capability in under a minute.