Overview

MCP is built into the default loop binary. Loop speaks the Model Context Protocol in both directions:
  • Client mode — Connect to external MCP servers and use their tools in your agent sessions
  • Server mode — Expose Loop’s built-in tools as an MCP server for other applications

MCP Client

Configuration

Add MCP servers in ~/.loop/agent/settings.json:

Transport Types

An Authorization: Bearer … header is sent as a static bearer token. Remote servers that need a browser sign-in use the OAuth flow below instead of a header.

Enable and disable

/mcp opens a picker. Space or Enter toggles the highlighted server.
on and off are aliases for enable and disable. ls is an alias for list. The choice is saved as disabledMcpServers in the global ~/.loop/agent/settings.json. A trusted project’s .loop/settings.json can add more names. Those names are combined with the global list.
A disabled server is not connected, and its tools are dropped. Enabling connects it and registers its tools. /mcp list shows each server and its state. Ctrl+O expands that server’s tool names. /mcp reload reconnects the enabled servers.

OAuth for remote servers

Remote HTTP servers that require sign-in use the OAuth authorization-code flow with PKCE. Login applies to servers configured with a url. A local command server does not use this flow.
/mcp login <name> opens the system browser (open on macOS, xdg-open on Linux, start on Windows), listens on 127.0.0.1 for the callback for three minutes, and stores tokens at ~/.loop/agent/mcp-auth/<name>.json (mode 0600 on Unix). A later connect loads that file. /mcp logout <name> deletes the file and disconnects. If the remote server accepts the session without OAuth, login says so and connects. A connect refused for missing credentials tells you to run /mcp login <name>. Logging in while a server is disabled saves the tokens. /mcp enable <name> connects it.

How it works

When you configure MCP servers, Loop’s McpClientManager connects to each enabled server and bridges their tools into the agent’s toolset. Bridged tools are named mcp__<server>__<tool> so they do not collide with read, write, edit, and bash.

MCP Server

Loop can expose its own tools as an MCP server over HTTP:

Options

Example

Other applications can now connect to http://127.0.0.1:3100/mcp and use Loop’s tools (read, write, edit, bash) via the MCP protocol.

Architecture

Securing the Server

The default bind is loopback (127.0.0.1), which may omit a token. Any other --mcp-host, including 0.0.0.0, is refused without --mcp-token:
Clients must include the token as a Bearer token in the Authorization header. Client and server are different process modes. /mcp runs inside the TUI. --serve-mcp listens over HTTP instead of starting the TUI. Use two processes if you want both at once: one Loop serving tools, another connecting to it (or to any other MCP server) as a client.