QA Spider MCP server: fix your site from Cursor, Claude and Codex

Connect your AI tool to QA Spider. It reads your audit findings and their fix prompts, fixes the code in your project and asks QA Spider to re-check. A finding counts as fixed only when a real check passes.

What it is

MCP is the standard way an AI tool talks to another service. QA Spider’s MCP server is one web address. Behind it, your AI tool can read your audit findings, tests, bugs and Helper documents, and ask QA Spider to run things for you.

The audit already writes a fix prompt for each finding. With MCP you stop copying it: your AI tool fetches the finding, makes the change in your own code, and, after you deploy, asks QA Spider to check that one finding again on your live site. QA Spider never edits your site.

A finding that fails, your AI tool editing the code to fix it, then QA Spider re-running that check and showing it as passed.

A finding fails, your AI tool changes your code, QA Spider re-runs that check. “Fixed” always comes from a check, never from your AI tool’s say-so.

Three steps to connect

  1. Add one address

    Paste the QA Spider server address into your AI tool, or run one command.

  2. Sign in or paste a key

    Sign in with your QA Spider account and choose the team and permissions, or use a connection key from your dashboard.

  3. Ask it to fix your site

    Tell your AI tool to fix your site’s findings. It reads them, edits your code, and asks QA Spider to re-check once you deploy.

The server address
https://www.qaspider.com/api/mcp

It also offers a ready-made prompt, fix_my_site, that walks your AI tool through the whole loop.

What your AI tool can do

Each action needs one of three permissions you choose on the consent screen: read looks, run starts work that can spend credits, and write changes data inside QA Spider.

Audit

The loop that fixes your site.

  • readList your audits and open one, with each finding’s severity and why it matters.
  • readOpen a finding with its fix prompt, as far as your plan shows it.
  • runStart an audit, under the same limits as the dashboard.
  • runRe-check one finding on your live site after you fix it.

Tests

Your projects and their runs.

  • readList projects and runs, and open the results of a run.
  • runRun tests. This spends testing credits.
  • runGenerate a test from a description. This needs Pro.

Bugs

Bugs inside QA Spider.

  • readList bugs and open one.
  • writeCreate and edit bugs inside QA Spider. Nothing is sent to a tracker.

Helper

Test plans and acceptance-criteria docs.

  • readList Helper documents and open one.
  • runGenerate a document. This spends credits.

Boost SEO

What to fix first in Google search. Pro.

  • readYour next actions, an indexing check of your public pages and how AI answers describe your site.
  • writeMark an action as done (“I did this”).

Connect your tool

There are two ways in. Sign in with your QA Spider account, or paste a connection key you create in your dashboard. Both give the connection one team and the permissions you choose.

7 of 15 setups were confirmed against the vendor’s own documentation on 2 October 2026. The rest are marked: tools change their settings often, so check the vendor’s page if a step does not match your version.

Chat apps

Claude (claude.ai and Desktop)

Custom connectors work in claude.ai, Claude Desktop and the mobile apps through your Claude account.

Sign inConnection keyPartly checked in the vendor’s docs
  1. Individual plans: open Customize, then Connectors, press + Add and choose Add custom connector. On Team and Enterprise, an owner adds it under Organization settings, Connectors, Add, Custom, Web.
  2. Name it QA Spider and paste the address: https://www.qaspider.com/api/mcp
  3. Press Connect and sign in with your QA Spider account, then choose the team and the permissions on the consent screen.
  4. Prefer a key? Under Request headers add one fixed header, Authorization with the value shown below.
Server address
https://www.qaspider.com/api/mcp
Request header (only if you use a key)
Authorization: Bearer qsp_YOUR_KEY

Claude connects from Anthropic’s cloud, not from your computer, so the server must be reachable from the internet. QA Spider is.

Free Claude accounts can add one custom connector.

The claude_desktop_config.json file is a separate mechanism for local servers; use the connector screen for a remote one.

We could not confirm this in the vendor’s docs: The exact field labels for the Request headers form (the vendor page names the section, not the fields). Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

ChatGPT

ChatGPT on the web can use a remote MCP server as a developer-mode app.

Sign inChecked in the vendor’s docs
  1. In ChatGPT on the web, turn on Developer mode (Settings, Security and login), then create an app from the plugins screen with the + button. OpenAI renames these screens often; the vendor page below has the current names.
  2. Choose a remote MCP server and paste the address: https://www.qaspider.com/api/mcp
  3. Choose OAuth as the authentication, then sign in with your QA Spider account and pick the team and permissions.
  4. The new app appears under Drafts, where you can switch individual tools on or off.
Server address
https://www.qaspider.com/api/mcp

Available on the web for Pro, Plus, Business, Enterprise and Education accounts.

OpenAI’s documentation lists OAuth or no authentication for these apps, not a bearer key, so use the sign-in here.

ChatGPT asks you to confirm any tool that is not marked read-only.

Checked against the vendor’s documentation.

Terminal agents

Claude Code

Anthropic’s coding agent for the terminal and the IDE.

Sign inConnection keyChecked in the vendor’s docs
  1. Run the add command below in your terminal.
  2. Start Claude Code and type /mcp. Choose qaspider and follow the browser sign-in, then pick the team and permissions.
  3. Prefer a key? Use the second command instead, with the key from your dashboard.
Add with sign-in
claude mcp add --transport http qaspider https://www.qaspider.com/api/mcp
Add with a connection key
claude mcp add --transport http qaspider https://www.qaspider.com/api/mcp \
  --header "Authorization: Bearer qsp_YOUR_KEY"
.mcp.json (shared with your team, key stays in your environment)
{
  "mcpServers": {
    "qaspider": {
      "type": "http",
      "url": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer ${QASPIDER_KEY}"
      }
    }
  }
}

Add --scope user to make it available in every project, or --scope project to write .mcp.json for your team. The default is local to the current project.

.mcp.json expands ${VAR}, so commit the file and keep the key in your shell environment.

Checked against the vendor’s documentation.

OpenAI Codex (CLI and IDE)

The Codex CLI, IDE extension and ChatGPT desktop app share one config file.

Sign inConnection keyChecked in the vendor’s docs
  1. Open ~/.codex/config.toml and add the block below.
  2. With a key: export QASPIDER_KEY=qsp_YOUR_KEY in the shell that starts Codex. Codex sends it as the bearer token.
  3. With sign-in: keep only the url line, then run the login command and approve the browser sign-in.
~/.codex/config.toml (connection key)
[mcp_servers.qaspider]
url = "https://www.qaspider.com/api/mcp"
bearer_token_env_var = "QASPIDER_KEY"
~/.codex/config.toml (sign-in)
[mcp_servers.qaspider]
url = "https://www.qaspider.com/api/mcp"
Then sign in
codex mcp login qaspider

Codex uses dynamic client registration when the server offers it, which QA Spider does.

Checked against the vendor’s documentation.

Gemini CLI

Google’s open-source terminal agent. Remote servers use httpUrl.

Connection keyPartly checked in the vendor’s docs
  1. Run the command below, or add the entry to ~/.gemini/settings.json (user) or .gemini/settings.json (project).
  2. Use a connection key: Gemini CLI’s documentation shows headers for this, and OAuth only with a client id you register yourself.
Add with a connection key
gemini mcp add --transport http -H "Authorization: Bearer qsp_YOUR_KEY" qaspider https://www.qaspider.com/api/mcp
~/.gemini/settings.json
{
  "mcpServers": {
    "qaspider": {
      "httpUrl": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer qsp_YOUR_KEY"
      }
    }
  }
}

The settings file holds your key in plain text. Use the user-level file, not one inside a repository.

We could not confirm this in the vendor’s docs: Sign-in without a pre-registered client id (the vendor page shows an oauth block that takes a clientId). Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

Warp

The Warp terminal’s agents can use URL-based MCP servers.

Connection keyPartly checked in the vendor’s docs
  1. Open Settings, Agents, MCP servers (or search “Open MCP Servers” in the Command Palette) and press + Add.
  2. Choose a Streamable HTTP or SSE server (URL) and paste the JSON below.
MCP server (JSON)
{
  "qaspider": {
    "url": "https://www.qaspider.com/api/mcp",
    "headers": {
      "Authorization": "Bearer qsp_YOUR_KEY"
    }
  }
}

Warp’s documentation describes browser sign-in for servers with built-in OAuth; use the key if it does not start.

We could not confirm this in the vendor’s docs: Whether sign-in works for a server Warp has no built-in setup for (the vendor page names OAuth only for some servers). Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

Editors and IDEs

Cursor

The AI code editor. One file holds every MCP server.

Connection keyPartly checked in the vendor’s docs
  1. Open ~/.cursor/mcp.json to use QA Spider in every project, or .cursor/mcp.json inside one project.
  2. Add the entry below. Cursor reads ${env:NAME} from your environment, so the key never goes in the file.
  3. Set the variable (export QASPIDER_KEY=qsp_YOUR_KEY) and restart Cursor.
  4. To sign in instead of using a key, leave out the headers block and approve the browser sign-in when Cursor asks.
~/.cursor/mcp.json
{
  "mcpServers": {
    "qaspider": {
      "url": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer ${env:QASPIDER_KEY}"
      }
    }
  }
}
Sign-in only
{
  "mcpServers": {
    "qaspider": {
      "url": "https://www.qaspider.com/api/mcp"
    }
  }
}

If the sign-in does not start, use the key. Cursor’s documentation shows static OAuth credentials, not automatic sign-in.

We could not confirm this in the vendor’s docs: Automatic OAuth sign-in with no client id: the vendor page documents only pre-registered OAuth credentials. Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

Google Antigravity

Google’s agent-first IDE. Remote servers use serverUrl, not url.

Sign inConnection keyChecked in the vendor’s docs
  1. Open Settings, Customizations, then the MCP config (global file ~/.gemini/config/mcp_config.json; a project can use .agents/mcp_config.json).
  2. Add the entry below. Use serverUrl: Antigravity does not accept url or httpUrl for remote servers.
  3. To sign in instead of using a key, leave out headers, then press Authenticate next to QA Spider under Installed MCP Servers.
~/.gemini/config/mcp_config.json
{
  "mcpServers": {
    "qaspider": {
      "serverUrl": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer qsp_YOUR_KEY"
      }
    }
  }
}
Sign-in only
{
  "mcpServers": {
    "qaspider": {
      "serverUrl": "https://www.qaspider.com/api/mcp"
    }
  }
}

The file holds your key in plain text. Keep it out of any repository.

Checked against the vendor’s documentation.

VS Code (GitHub Copilot)

Visual Studio Code with Copilot agent mode.

Sign inConnection keyChecked in the vendor’s docs
  1. Run “MCP: Open User Configuration” from the Command Palette (or create .vscode/mcp.json in a project).
  2. Add the entry below. The inputs block makes VS Code ask for your key once and store it, so it is never in the file.
  3. To sign in instead, leave out headers and inputs; VS Code opens the browser on first use.
mcp.json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "qaspider-key",
      "description": "QA Spider connection key",
      "password": true
    }
  ],
  "servers": {
    "qaspider": {
      "type": "http",
      "url": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer ${input:qaspider-key}"
      }
    }
  }
}
Sign-in only
{
  "servers": {
    "qaspider": {
      "type": "http",
      "url": "https://www.qaspider.com/api/mcp"
    }
  }
}

The top-level key is servers (not mcpServers) in VS Code.

Checked against the vendor’s documentation.

Windsurf

The Cascade agent editor. Remote servers use serverUrl.

Connection keyPartly checked in the vendor’s docs
  1. Open mcp_config.json from the MCP settings in Cascade (the vendor page lists where the file lives on each system).
  2. Add the entry below and set QASPIDER_KEY in your environment. Windsurf reads ${env:NAME} inside headers.
mcp_config.json
{
  "mcpServers": {
    "qaspider": {
      "serverUrl": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer ${env:QASPIDER_KEY}"
      }
    }
  }
}

The vendor page says OAuth is supported for each transport but does not show the steps, so this page documents the key.

We could not confirm this in the vendor’s docs: The OAuth sign-in steps. Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

Zed

The Zed editor lists remote servers under context_servers.

Sign inConnection keyChecked in the vendor’s docs
  1. Run “zed: open settings file”, or use Settings, AI, MCP Servers.
  2. Add the entry below. With no Authorization header, Zed starts the standard MCP sign-in for you.
settings.json (connection key)
{
  "context_servers": {
    "qaspider": {
      "url": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer qsp_YOUR_KEY"
      }
    }
  }
}
settings.json (sign-in)
{
  "context_servers": {
    "qaspider": {
      "url": "https://www.qaspider.com/api/mcp"
    }
  }
}

The settings file holds your key in plain text. Zed settings are often synced or committed, so prefer the sign-in.

Checked against the vendor’s documentation.

Cline

The Cline extension for VS Code and JetBrains.

Connection keyPartly checked in the vendor’s docs
  1. In Cline, open the MCP Servers icon, then Configure, then Configure MCP Servers.
  2. Add the entry below. Set type to streamableHttp: leaving it out selects the older SSE transport.
cline_mcp_settings.json
{
  "mcpServers": {
    "qaspider": {
      "type": "streamableHttp",
      "url": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer qsp_YOUR_KEY"
      },
      "disabled": false,
      "autoApprove": []
    }
  }
}

The file holds your key in plain text; keep autoApprove empty so Cline asks before each tool call.

We could not confirm this in the vendor’s docs: Sign-in without a key (the vendor page shows headers only). Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

Continue

The Continue extension. MCP works in agent mode only.

Connection keyPartly checked in the vendor’s docs
  1. Create .continue/mcpServers/qaspider.yaml in your project.
  2. Paste the file below and store the key as a Continue secret named QASPIDER_KEY.
  3. Switch Continue to agent mode: MCP tools are not available in chat mode.
.continue/mcpServers/qaspider.yaml
name: QA Spider
version: 0.0.1
schema: v1
mcpServers:
  - name: QA Spider
    type: streamable-http
    url: https://www.qaspider.com/api/mcp
    requestOptions:
      headers:
        Authorization: "Bearer ${{ secrets.QASPIDER_KEY }}"

We could not confirm this in the vendor’s docs: Sign-in without a key, and how a secret is stored locally (the vendor page shows only the ${{ secrets.NAME }} syntax). Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

JetBrains AI Assistant

IntelliJ IDEA, PyCharm, WebStorm and the other JetBrains IDEs.

Connection keyPartly checked in the vendor’s docs
  1. Open Settings, Tools, AI Assistant, Model Context Protocol (MCP), press Add and paste the JSON below.
  2. A remote server needs a recent AI Assistant release with Streamable HTTP support. If Add rejects the URL, update the IDE or use the mcp-remote bridge below.
MCP settings (JSON)
{
  "mcpServers": {
    "qaspider": {
      "url": "https://www.qaspider.com/api/mcp",
      "headers": {
        "Authorization": "Bearer qsp_YOUR_KEY"
      }
    }
  }
}

JetBrains does not expand environment variables in this file, so the key is stored in the IDE settings.

We could not confirm this in the vendor’s docs: The headers field (the JetBrains AI Assistant page shows only url; the headers example comes from JetBrains’ YouTrack documentation). The first release that supports remote URLs, and OAuth sign-in. Check the vendor’s page before relying on it.

Checked against the vendor’s documentation.

Anything else

Any other client (mcp-remote bridge)

For clients that only start local (stdio) servers. The open-source mcp-remote package turns QA Spider into one.

Sign inConnection keyChecked in the vendor’s docs
  1. You need Node.js. In your client’s MCP config add the entry below (the same mcpServers shape Claude Desktop, Cursor and Windsurf use for local servers).
  2. With no header, mcp-remote opens the browser for the sign-in and keeps the tokens on your computer.
  3. With a key, pass it in an environment variable. Write the header as Authorization:${QASPIDER_AUTH} with no space after the colon: some clients mangle spaces inside args, and a space inside the environment variable is fine.
Sign-in
{
  "mcpServers": {
    "qaspider": {
      "command": "npx",
      "args": [
        "mcp-remote",
        "https://www.qaspider.com/api/mcp"
      ]
    }
  }
}
Connection key
{
  "mcpServers": {
    "qaspider": {
      "command": "npx",
      "args": [
        "mcp-remote",
        "https://www.qaspider.com/api/mcp",
        "--header",
        "Authorization:${QASPIDER_AUTH}"
      ],
      "env": {
        "QASPIDER_AUTH": "Bearer qsp_YOUR_KEY"
      }
    }
  }
}

mcp-remote is a separate open-source project, not made by QA Spider. Drop it as soon as your client supports remote servers directly.

Checked against the vendor’s documentation.

A connection key looks like qsp_ followed by random characters. It is shown once when you create it, stored only as a hash, and you can revoke it at any time. Treat it like a password: use an environment variable rather than pasting it into a file you commit.

What it can and cannot do

It can

  • Read your audits, findings, tests, runs, bugs and Helper documents.
  • Start an audit, re-check a finding, run and generate tests, under your plan’s limits.
  • Create and edit bugs, and mark Boost SEO actions as done, inside QA Spider.

It cannot

  • Send anything to Jira, Linear, GitHub, ClickUp, Slack, Discord or Telegram. That stays in the dashboard.
  • Edit your site or your code. Your AI tool does that, and you deploy.
  • See another team’s data, or check an address that is not your audited site.
  • Mark a finding fixed without a passing check.

Search Console data is a separate permission

Your Google Search Console data stays out of MCP unless you allow it. It has its own checkbox on the consent screen, it is off by default, you can withdraw it at any time, and it needs Pro ($29/mo) with Boost SEO connected.

Without that permission QA Spider does not send your Search Console data to an AI tool, and QA Spider itself never sends it to an AI model. If you allow it, the AI tool you chose receives that data because you asked it to, and what it does next is governed by that tool’s own terms.

This is separate from the read-only Boost SEO dashboard, where the data is shown to you and nowhere else.

This permission is not open yet. It comes later than the rest, after Google has reviewed our updated privacy policy.

How the connection is kept safe

Sign in or revocable keys

Sign in with OAuth, or use a connection key you create and revoke yourself. A key is shown once and stored only as a hash.

One team per connection

Each connection is bound to one team you choose. A member cannot do through MCP what the dashboard reserves for owners and admins.

Membership checked every call

If you are removed from a team, its connections stop working immediately.

An audit log

Every run and write call is logged: who, which tool, which AI client, when, and for which team. You see it in the dashboard.

You choose the permissions

Read, run and write are separate boxes on the consent screen, and each tool is marked read-only, writing or destructive so your AI tool can ask before it acts.

Your site’s text is treated as data

Text from your own pages that comes back in a result is labelled as untrusted, so a page cannot give instructions to your AI tool. Tokens and secrets are never returned.

Every plan, the same limits as the dashboard

MCP costs nothing extra. What you can do through it is what your plan lets you do in the dashboard, and when a limit blocks an action your AI tool gets a plain message with the link to upgrade.

Free and Solo

Audits and findings as in the dashboard: Free shows the first findings and the top fix prompt, Solo ($12/mo) unlocks every finding and the full fix prompt.

Pro

Boost SEO, AI answers, and test generation (up to 100 a month). Running and generating tests spends the 1,000 testing credits a month that come with Pro ($29/mo).

Questions about MCP

What is the QA Spider MCP server?

The QA Spider MCP server is one web address that lets your AI tool (Cursor, Claude, Codex, ChatGPT and others that support MCP) work with your QA Spider account. It reads your audit findings and their fix prompts, fixes the code in your own project, and asks QA Spider to re-check the finding.

Can I use it today?

Yes. Add the address to your AI tool and sign in with your QA Spider account, or create a connection key in your dashboard. The steps for each tool are on this page.

Does QA Spider change my code or my site?

No. Your AI tool edits the code in your own project, on your computer, and you deploy it. QA Spider only reads your results, runs the checks and tests you allow, and records what happens inside QA Spider.

When is a finding marked fixed?

A finding is marked fixed only when QA Spider re-runs that finding’s check against your live site and it passes. If a check cannot be run on its own, such as page speed or a link crawl, QA Spider tells your AI tool to run a full audit instead of guessing.

Can the MCP server send bugs to Jira or messages to Slack?

No. Nothing is sent to a bug tracker or a chat tool through MCP. Your AI tool can create and edit bugs inside QA Spider; sending them on stays a button in the dashboard that you press.

Does my AI tool get my Search Console data?

No. Search Console data is not available through MCP yet. It will be a separate permission that is off by default, has its own checkbox on the consent screen and can be withdrawn at any time, and it opens only after Google has reviewed our updated privacy policy. Until then, QA Spider never sends your Search Console data to an AI tool.

Does it cost extra?

No. MCP works on every plan, with the same limits as the dashboard. Free shows the same findings it shows in the dashboard, Boost SEO, AI answers and Search Console need Pro ($29/mo), and running or generating tests spends the same testing credits.

How do I disconnect an AI tool?

Disconnect it from the connected AI tools page in your dashboard, or revoke its connection key. The connection stops working at once, and it also stops if you are removed from the team it is connected to.

No findings yet? Run the free audit first, then connect your tool.