Kernl

Claude Code

This page connects the Claude Code command-line app to Kernl, so Claude Code can use Kernl's tools. "Claude Code" also names a different feature, where Kernl uses your Claude subscription as its AI. That one is in Connect a model.

You need Kernl running and your token. See First run if you do not have it.

Add Kernl

On Linux, with kernl on your PATH:

claude mcp add --transport http -s user kernl http://localhost:3086/mcp --header "Authorization: Bearer $(kernl token)"

-s user makes Kernl available in every project. Use -s local (Claude Code's default) for the current project only, private to you. Do not use -s project with a token: it writes the server into .mcp.json at the repository root, which is meant to be committed, so your token would end up in git. Keep the order as shown: name, URL, then --header.

macOS and Windows steps come from Kernl's packaging; the Kernl team has not run them on those systems yet.

On macOS, replace $(kernl token) with the full path:

claude mcp add --transport http -s user kernl http://localhost:3086/mcp --header "Authorization: Bearer $(/Applications/Kernl.app/Contents/MacOS/kernl token)"

With Docker, run it from the Kernl folder. The -T stops Docker from allocating a terminal, so the token comes back as clean text. We did not run this exact line (not run by us); the plain docker compose exec kernel cat /app/data/.kernel-auth-token is what we verified:

claude mcp add --transport http -s user kernl http://localhost:3086/mcp --header "Authorization: Bearer $(docker compose exec -T kernel cat /app/data/.kernel-auth-token)"

On Windows, print the token with .\start.bat token, then paste it into the command in place of <token>:

claude mcp add --transport http -s user kernl http://localhost:3086/mcp --header "Authorization: Bearer <token>"

Claude Code confirms with Added HTTP MCP server kernl and hides the token in that message.

Check the connection

claude mcp list

You should see:

kernl: http://localhost:3086/mcp (HTTP) - ✔ Connected

Inside a Claude Code session you can also type /mcp to see the server and its tools.

Careful with claude mcp get

claude mcp get kernl prints your Authorization header in full, token included. Do not paste its output into a chat, an issue or a screenshot.

When it does not connect

A wrong token looks like this:

kernl: http://localhost:3086/mcp (HTTP) - ✘ Failed to connect — Server rejected the configured Authorization header (HTTP 401). ...

A missing token gives a different, misleading message:

kernl: http://localhost:3086/mcp (HTTP) - ✘ Failed to connect — JSON Parse error: Unrecognized token '<'

Both mean the token is missing or wrong. See 401 Unauthorized and Unexpected token '<'. To fix it, remove the server and add it again with a fresh token.

claude mcp remove kernl -s user