POST /api/v1/mcp on the on-prem host. Point your coding agent at the local URL and you get the identical tool surface (Flow CRUD, block ops, wiring, variables, publish, traces).
The URL
- The desktop app and compose paths default to
http://localhost:8090/api/v1/mcp. ChangeNORA_HOST_PORTin.env.onpremif that port is taken — the MCP URL moves with it. - The Kubernetes path uses whatever hostname you set for
publicUrlin the Helm chart (for examplehttps://nora.example.internal/api/v1/mcp). See Kubernetes (Helm).
Connecting
- Claude Code
- Codex CLI
- Cursor / other hosts
nora-localis just the alias Claude Code shows in its tool list — pick a name that distinguishes it from any SaaSnoraentry you already have.--scope userwrites it to~/.claude.jsonso every project on this laptop sees the local server. Drop the flag to register only in the current project.- The first tool call opens an OAuth login in your browser against your own local server. Sign in with a Nora Local account and grant
read·build·run.
OAuth requires NORA_PUBLIC_URL to match
The OAuth flow bounces the browser back to a callback URL the server advertises. That URL comes fromNORA_PUBLIC_URL (and NORA_OAUTH_REDIRECT_BASE), so both need to match the URL your browser actually hits.
- Localhost defaults —
http://localhost:${NORA_HOST_PORT:-8090}works out of the box for the desktop app and single-host compose. - Reverse proxy or ingress — set
NORA_PUBLIC_URL=https://nora.example.internal(or Helm’spublicUrl) to the public URL. Otherwise the OAuth callback lands onhttp://localhost:8090, the browser can’t reach it, and the login stalls.
Alongside a SaaS entry
Register both with different aliases so tool names stay unambiguous.nora_list_flows and nora-local_list_flows are cleanly separated.
What’s exposed
The tool surface is identical to SaaS — see MCP tool surface for the full list. Permissions mirror your Nora Local role: a Guest can only read; approval-gated actions still go through the approval flow when run over MCP.Air-gap notes
Nothing about MCP requires internet access — the whole flow (OAuth login, tool calls) stays on your local host.- If
NORA_AIRGAP=1is on, the server still serves MCP normally. The boot probe only checks the server can’t reach the public internet; it doesn’t restrict inbound traffic from the local browser or CLI. - For headless server installs where the target host has no browser, run the coding agent on a laptop that can reach the server over the LAN, and set
NORA_PUBLIC_URLto the LAN hostname (http://nora.internal:8090) so the OAuth callback lands somewhere your browser can hit.
Troubleshooting
connection refusedonclaude mcp add. The stack isn’t up. Checkdocker psor the desktop app tray. The URL must include the scheme (http://, not justlocalhost:8090).- OAuth login page 404s or hangs.
NORA_PUBLIC_URLdoesn’t match the URL your browser is on. Set it to the exact base URL (scheme + host + port) you’re using and restart the stack. - Tool list is empty after login. The account you signed in with has no workspace access on this server. Check permissions on the SPA (
Settings → Members), then reconnect. nora-localandnoracollide. They don’t — Claude Code prefixes tool names per server. If tools appear duplicated in the picker, restart the host so the tool list refreshes.
Related
MCP (SaaS)
The same page for the hosted
platform.nora.my server.Settings — host port
Change
NORA_HOST_PORT when the default 8090 is taken.Kubernetes (Helm)
publicUrl chart value and ingress setup.