MCP for developers
Comigo can run a local, read-only Model Context Protocol server so your AI tools can use the context Comigo already has: what you are focused on, your tasks and your app workflow.
- Listens only on
127.0.0.1. Off by default. - Requires a bearer token, generated in Comigo. The client environment variable is
COMIGO_MCP_TOKEN. - Read-only. It can't capture anything new, edit tasks, run a model or perform actions.
- Never returns screenshots, OCR text, audio transcripts, conversations, embeddings or credentials.
- Pause and privacy exclusions apply to every request.
Turn it on
- Open Settings → MCP (or Settings → Integrations and pick your app).
- Review the suggested free port (Suggest free port finds another; port
0lets the system pick). - Turn on Enable MCP and click Generate token.
- Copy the URL (
http://127.0.0.1:PORT/mcp) and the configuration for your client.
Comigo must stay running. The server stops when Comigo quits; enabling it again creates a new token, so reconnect your client after a restart.
Client setup
Codex
~/.codex/config.toml:
[mcp_servers.ai2_copilot]
url = "http://127.0.0.1:YOUR_PORT/mcp"
bearer_token_env_var = "COMIGO_MCP_TOKEN"
Then make COMIGO_MCP_TOKEN available to the Codex process. Apps opened from Finder may not inherit your terminal's environment.
Cursor
.cursor/mcp.json (project) or ~/.cursor/mcp.json (global):
{
"mcpServers": {
"ai2_copilot": {
"url": "http://127.0.0.1:YOUR_PORT/mcp",
"headers": { "Authorization": "Bearer ${env:COMIGO_MCP_TOKEN}" }
}
}
}
VS Code / GitHub Copilot
.vscode/mcp.json — VS Code prompts for the token and stores it securely:
{
"inputs": [
{ "type": "promptString", "id": "comigo-token", "description": "Comigo access token", "password": true }
],
"servers": {
"ai2_copilot": {
"type": "http",
"url": "http://127.0.0.1:YOUR_PORT/mcp",
"headers": { "Authorization": "Bearer ${input:comigo-token}" }
}
}
}
Raycast AI (Pro)
Add an MCP server with URL http://127.0.0.1:YOUR_PORT/mcp and the HTTP header Authorization: Bearer YOUR_TOKEN.
Other clients
Any client that supports Streamable HTTP with a custom Authorization: Bearer … header works. Browser-based clients, OAuth-only clients and remote tunnels are not supported by design.
Tools
| Tool | Returns | Arguments |
|---|---|---|
copilot_current_context |
Focused app and window title, when permitted. Does not take a new screenshot | — |
copilot_list_tasks |
Recent task titles, goals, summaries, completion state | limit (default 20, max 100), include_completed (boolean, default false) |
copilot_workflow |
App visits, window titles, meeting flag, active time, transitions | start, end (required, Unix ms, max 7 days), limit |
copilot_search_memories |
Saved memories — only if "Share saved memories" is on (off by default) | query (≤ 200 chars), limit |
Limits: text fields ≤ 4,000 characters, results ≤ 100 records; memory search covers the newest 1,000 memories.
Treat returned task and memory text as untrusted user content, not as instructions for your assistant.
Security model
- Binds to IPv4
127.0.0.1only. A correctHostheader and bearer token are required. - Every request with an
Originheader is rejected (no browser access, no DNS rebinding, no CORS). - Tokens live only in memory and are never written to disk; disabling MCP closes the listener and enabling it rotates the token.
- Paused monitoring returns no data. Excluded apps and private-browsing/password-manager shields are applied per request; tasks whose evidence is missing or excluded are omitted.
Protocol details
- Transport: MCP Streamable HTTP. JSON-RPC
POST→ JSON response; notifications →202;GETstreaming →405. - Stateless; no
Mcp-Session-Id. - Protocol versions:
2025-03-26,2025-06-18,2025-11-25. Unknown versions at initialize negotiate2025-06-18; an unsupportedMCP-Protocol-Versionheader →400. - Request body ≤ 64 KiB; at most 8 concurrent authenticated requests (more →
429).
Quick test with curl:
curl -s http://127.0.0.1:YOUR_PORT/mcp \
-H "Authorization: Bearer $COMIGO_MCP_TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
