> For the complete documentation index, see [llms.txt](https://docs.does.qa/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.does.qa/doesqa-ai/doesqa-ai/mcp.md).

# MCP

Connect an AI coding agent to DoesQA over MCP: tools, auth, Assistant, memory, review, and DoesQA Sync.

Model Context Protocol (**MCP**) is how an AI coding agent connects to your DoesQA account. One connection exposes **46** tools over `https://mcp.ai.does.qa/mcp`. The agent can author Flows and Test Steps, manage Elements, start Runs, read Results and traces, ask the in-app [Assistant](/doesqa-ai/doesqa-ai.md#assistant), and store durable memory.

The [CLI](/doesqa-ai/doesqa-ai/cli.md) is the same bridge with a terminal on the front. Both use the same [access token](/doesqa-ai/doesqa-ai/access-tokens.md), so a team can use either without a second setup.

The [Flow Builder](/platform/flow-builder.md) stays the primary way people author Tests. MCP is how an agent joins in.

## What the agent can do

The tools cover twelve areas of the platform, including:

* Flows, Test Cases, and Test Steps
* Elements
* Run Recipes
* Runs, Results, artefacts, and traces
* Coverage, failure patterns, and Suggestions
* Knowledge search
* The in-app Assistant
* Durable agent memory
* A read-only account mirror for [DoesQA Sync](#doesqa-sync)

The agent works with product data. Pass and fail still come from real browsers and the Steps you (or the agent) configured.

## Connect

{% stepper %}
{% step %}

## Add the DoesQA server

In your MCP client (Cursor, Claude Desktop, Claude Code, or another client that speaks MCP), add a server with this URL:

```json
{
  "mcpServers": {
    "doesqa": { "url": "https://mcp.ai.does.qa/mcp" }
  }
}
```

The URL is enough. Keep the access token out of this file.
{% endstep %}

{% step %}

## Approve the connection in DoesQA

The client opens a browser and sends you to DoesQA. Sign in if DoesQA asks you to.

**Create Access Token** opens on **Settings → User**. The title may already match your client. Choose **30 Days**, **60 Days**, or **90 Days**, then save.

DoesQA passes the token to the client and sends you back to the agent. The account comes from the token.
{% endstep %}
{% endstepper %}

If the dialog does not open on its own, choose **Create Token** on that page. If your client asks you to paste a token, create one and copy it once. Full steps: [Access tokens](/doesqa-ai/doesqa-ai/access-tokens.md).

Treat the token like a password. Keep it out of chat, and keep it out of source control.

{% hint style="info" %}
**Pro tip:** Start a session by asking the agent to list tools or to ask the Assistant how login is already covered in this account. That grounds the next change in your real Flows.
{% endhint %}

## Control agent access

Connecting an agent is a security decision. You stay in control from [Access tokens](/doesqa-ai/doesqa-ai/access-tokens.md):

| Control       | What it means                                                                                                                                             |
| ------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Your user** | The token acts as you on the account you created it in. Each person creates their own.                                                                    |
| **Duration**  | **30 Days**, **60 Days**, or **90 Days**. [Renew](/doesqa-ai/doesqa-ai/access-tokens.md#renew-edit-or-delete) resets the expiry and keeps the same token. |
| **Delete**    | Stops the token immediately. Anything using it stops working.                                                                                             |

The same controls are summarised on [Security](/platform/security.md#agent-access-mcp-and-cli).

## Ask the Assistant

The agent can put a question to the in-app Assistant and get an answer grounded in this account’s Flows, Tests, Runs, failures, coverage, Elements, and product knowledge.

On this path the Assistant is read-only for the agent’s question, so asking cannot change account data. The exchange is an ordinary conversation in the app: you can open it and read what the agent asked and what it was told.

The Assistant answers. The agent acts on that answer when it authors or updates Tests.

## Memory for agents

The agent can store a durable fact and recall it later: conventions, recurring fixes, decisions about your environment.

| Scope              | Who recalls it                                                                                                                   |
| ------------------ | -------------------------------------------------------------------------------------------------------------------------------- |
| **user** (default) | Private to the person behind the token. Their agents recall it in any tool and any session.                                      |
| **account**        | Shared with every token on the account, so the whole team’s agents can recall it. Set this scope deliberately when you remember. |

Recall also surfaces the in-app Assistant’s memory read-only. Each hit is tagged by source, so you can see whether a fact came from an agent or from the Assistant.

Never store secrets in memory.

This store is separate from [Automation Intelligence Learning](/doesqa-ai/doesqa-ai.md#how-learning-works). Learning improves summaries, Suggestions, and the Assistant. Agent memory is stored facts the agent (and, for account scope, the team’s agents) can retrieve on demand.

## Review agent work

When the agent creates or changes something, or starts a Run, it should hand you a review link into DoesQA. Open it and read the work as product data:

* A [Flow](/platform/flow-builder.md) on the canvas, with its Test Cases and Test Steps
* A [Run](/runs/runs.md) with Results, screenshots, and traces when the runner provides them
* An Assistant conversation, when the agent asked a question

Review is reading a journey and its evidence, not reading a pile of generated test code.

## Work that stays in the platform

Flows the agent saves, Runs it queues on hosted runners, Results it records, and memory it stores all live in DoesQA. A person or a [Schedule](/configuration/schedules.md) can pick the work up later. The agent does not have to stay connected for that work to remain.

## DoesQA Sync

[DoesQA Sync](/getting-started/terminology.md) is the read-only mirror of your account under `.doesqa/`. Use the [CLI](/doesqa-ai/doesqa-ai/cli.md#doesqa-sync) to pull it:

* `.doesqa/flows/<slug>-<id>.flow.md`: YAML front matter, a Mermaid diagram of the Flow, and a compact JSON step map
* `.doesqa/elements/*.element.json` and `.doesqa/recipes/*.recipe.json`: flat records

Output is deterministic, so committing `.doesqa/` gives reviewable diffs. Treat the mirror as reference. Edit Tests through MCP tools or the [CLI](/doesqa-ai/doesqa-ai/cli.md), or in the app, not by hand in those files.

## Related

* [Access tokens](/doesqa-ai/doesqa-ai/access-tokens.md)
* [CLI](/doesqa-ai/doesqa-ai/cli.md)
* [DoesQA AI](/doesqa-ai/doesqa-ai.md)
* [Platform → DoesQA AI](/platform/doesqa-ai.md)
* [Security](/platform/security.md#agent-access-mcp-and-cli)
* [Flow Builder](/platform/flow-builder.md)
* [Runs](/runs/runs.md)
* [Integrations](/platform/integrations.md)
