Layovelle

Authentication

Documentation

Legacy. This section documents the original Layovelle MCP server at mcp.moda.app/mcp, built around start_design_task and get_moda_canvas. It is superseded by Layovelle for Agents — the moda CLI wherever your agent has a shell, and the Layovelle connector for claude.ai and other chat hosts. The connector replaces this server, so the tools below retire with it. These pages stay published for existing integrations; start new ones on Layovelle for Agents.
The hosted MCP server at mcp.moda.app/mcp supports two authentication methods. Pick whichever matches how you’ll be invoking it.

Which method should I use?

OAuth 2.1 — pick this when a human is driving

Use cases How it works. On first use, your client pops a browser, you sign in to Layovelle (via Clerk), and tokens get stored by the client. Every subsequent tool call is authenticated silently — you won’t see the sign-in again unless your session expires or you revoke access. Individual team members see their own canvases, orgs, and credits. What you get. Per-user identity. Every tool call runs as you; list_my_canvases returns the canvases you personally have access to, design tasks bill against your team’s credits, and audit logs attribute actions to your user. Use cases How it works. Generate a key in Settings → Developer → REST API, then configure your MCP client to send Authorization: Bearer moda_live_.... The key ties every tool call to the team it was created under. What you get. Team-level identity. Every call runs as the key’s owner + team.

Rules of thumb

Mixing both

The server accepts both methods simultaneously — you can have your own Cursor connected via OAuth, and a Claude Managed Agent connected with an API key, against the same Layovelle account. They don’t conflict; pick the right auth for each caller.

When is authentication required?

Public share links work without authentication in both local and remote server modes. Private canvases and canvas listing/searching require the remote server with either OAuth or an API key.

Setting up API-key auth

1. Generate a key

In your Layovelle account, go to Settings → Developer → REST API → Create API key. Creating a key requires a paid plan — a free workspace is asked to upgrade under Settings → Billing first. Existing keys keep working either way. Copy the moda_live_... key — it’s shown once. Store it in a secret manager.

2. Configure your client

The URL must come immediately after the server name; --header uses an HTTP-style Name: value format with a colon, not =.--scope user keeps the key in your per-user Claude config rather than a repo-level file that could get committed.
Claude Desktop and claude.ai don’t support custom headers in their connector UI today — they assume OAuth for remote MCPs, so use OAuth there. Cursor, VS Code and Claude Code support both: they can sign in over OAuth, and they accept a header, so a key is simply the simpler choice for unattended or shared-credential use. CI and cron have no browser step and need a key. Some chat hosts ask for a key even with a person present — Meta’s Muse does. Match what the host offers, not whether someone is watching.

3. Identity

Every tool call authenticated with an API key runs as the key’s owner + team. list_my_canvases returns the key-owner’s canvases; start_design_task bills their team’s credits. Session context (set_context) persists per-user across calls, same as OAuth — different keys mean different owners, so multi-tenant reuse is safe.

4. Rotating or revoking a key

Go to Settings → Developer → REST API, revoke the key, and generate a new one. Update the bearer token in your MCP client config. No coordination with end-users needed — API keys are meant to rotate.

How the OAuth flow works

When you first use the MCP server, your editor initiates the OAuth flow:
  1. Your editor sends a request to the MCP server
  2. The server responds with 401 Unauthorized
  3. Your editor discovers the OAuth endpoints automatically
  4. A browser window opens for you to sign in via Layovelle (powered by Clerk)
  5. After sign-in, tokens are exchanged and stored by your editor
  6. All subsequent requests are authenticated automatically
If you’re already signed in to layovelle.com in your browser, the sign-in step is instant — your existing session is detected automatically.

Token lifecycle

Your editor manages token refresh transparently. You should rarely need to re-authenticate unless you revoke access or your refresh token expires.

Local server authentication

The local stdio server does not use authentication. It can only access public share links. To access private canvases, use the remote server at mcp.moda.app.

Revoking access

OAuth sessions — remove the connector in the client: This removes the stored tokens locally. You’ll re-authenticate on next connect. API keys — revoke the key itself at Settings → Developer → REST API. Every client using that key loses access immediately across all sessions and devices. Generate a fresh key and update your client config to continue.

Security