Skip to content

Getting Started (end-to-end)

This is the full path from zero to a working MCP connection and your first tool call. No prior context assumed. Budget about five minutes.

You'll need

  • A DevFellowship account (you sign in with GitHub).
  • Node.js 20 or newer — only for the one-time login CLI. Check with node -v.
  • An MCP-compatible client: Claude Code, Cursor, VS Code, codex, or the Anthropic SDK. Any one is fine.

The dfl-auth CLI runs the GitHub OAuth flow and stores your token locally. No install needed — npx fetches it on demand.

  1. Configure the Supabase project (one time per machine):

    Terminal window
    npx @devfellowship/dfl-auth configure
  2. Log in — this opens your browser for GitHub OAuth:

    Terminal window
    npx @devfellowship/dfl-auth login
  3. Confirm you’re authenticated:

    Terminal window
    npx @devfellowship/dfl-auth status

Your credentials are written to ~/.dfl-mcp/:

FileContents
~/.dfl-mcp/project.jsonSupabase project configuration
~/.dfl-mcp/credentials.jsonaccess_token + refresh_token + expires_at

Prefer a global install?

Terminal window
npm install -g @devfellowship/dfl-auth
dfl-auth login

The DFL MCP is split into 14 hosts, one per area. Add only the hosts you need. All hosts use the same login; only the tool set changes.

thumbnail.mcp.devfellowship.com is an alias of the Lesson Studio host until 2026-12-04. Use studio.mcp.devfellowship.com for generate_thumbnail.

HostEndpointUse it for
Learnhttps://learn.mcp.devfellowship.com/mcpmembers, profiles, courses, lessons, programs, progress, wiki
Workhttps://work.mcp.devfellowship.com/mcpprojects, epics, deliveries, tasks, business units, placements
Engineeringhttps://engineering.mcp.devfellowship.com/mcpspec runs, task assignment, diagrams, documents, sheets, UX maps
Planshttps://plans.mcp.devfellowship.com/mcpplans, ADRs, questions
Paymentshttps://payments.mcp.devfellowship.com/mcptransactions, fellow payments (invoices)
Accounting ledgerhttps://financing.mcp.devfellowship.com/mcpaccounts, journal entries, ingest, reconciliation
Lesson Studiohttps://studio.mcp.devfellowship.com/mcpvideo lessons, slides and YouTube thumbnails
Campaignshttps://campaigns.mcp.devfellowship.com/mcpsocial posts, review queue, analytics
Strategyhttps://strategy.mcp.devfellowship.com/mcpBusiness Model Canvas, personas, competitors
Proposalshttps://proposals.mcp.devfellowship.com/mcppublic tenders, answer library, submissions
Eventshttps://events.mcp.devfellowship.com/mcpevents, sessions, guests, check-in
Forms & quizzeshttps://quiz.mcp.devfellowship.com/mcpforms, quizzes, interview dispatch
Platform (ops)https://ops.mcp.devfellowship.com/mcpidentity, IAM, apps, media, sandboxes, agent comms
Skillshttps://skills.mcp.devfellowship.com/mcpDFL Forge skills

Each host page lists every tool with its parameters. All MCP hosts groups them by goal.

Pick your client below. Replace YOUR_ACCESS_TOKEN with the token from step 1. Add or remove server blocks to match the hosts you want.

Add to your project’s .mcp.json (or the global ~/.claude/mcp.json). One block per domain:

.mcp.json
{
"mcpServers": {
"dfl-work": {
"type": "http",
"url": "https://work.mcp.devfellowship.com/mcp",
"headers": { "Authorization": "Bearer YOUR_ACCESS_TOKEN" }
},
"dfl-learn": {
"type": "http",
"url": "https://learn.mcp.devfellowship.com/mcp",
"headers": { "Authorization": "Bearer YOUR_ACCESS_TOKEN" }
}
}
}

Then restart Claude Code (or run /mcp to reconnect). You should see the dfl-work / dfl-learn tools appear.

Once the client connects, just ask in natural language — the model picks the tool. Try:

“List my projects.” → calls list_projects on dfl-work

“What courses am I enrolled in?” → calls list_courses / list_members on dfl-learn

Want to verify the wiring without a client? Hit any endpoint directly:

Terminal window
# Health (no auth) — should return {"status":"ok", ...}
curl https://work.mcp.devfellowship.com/health
# Initialize a session (auth required)
curl -X POST https://work.mcp.devfellowship.com/mcp \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0", "id": 1, "method": "initialize",
"params": {
"protocolVersion": "2024-11-05",
"capabilities": {},
"clientInfo": { "name": "curl-test", "version": "1.0.0" }
}
}'

A 200 with a result means you’re connected. See every host and its tools in All MCP hosts.

Your token is missing, malformed, or expired.

  • Confirm the header format is exactly Authorization: Bearer <token> (one space).
  • Tokens expire — renew with the token refresh flow.

You’re authenticated, but your permissions don’t allow this. The MCP runs every call as you under Row-Level Security, so you only see/modify what your IAM role permits. This is expected, not a bug — see Auth & security.

Tokens are short-lived. Renew without re-running the browser login:

Terminal window
npx @devfellowship/dfl-auth refresh
  • Use the dotted host scheme: work.mcp.devfellowship.com. The old dashed scheme (mcp- in front of the domain name) no longer resolves.
  • The tools path is always /mcp. /health is open; /mcp requires auth.

Clear the npx cache and retry:

Terminal window
rm -rf ~/.npm/_npx

Each endpoint rate-limits (~100 req/min by default). Back off and retry.