You can also restrict the session to
read-only MCP tools
, limit it to specific MCP tools or feature categories using
MCP tool filtering
, and pin the agent to a specific organization or project to limit blast radius.
Advanced configuration
Using an API key instead of OAuth
If your MCP client doesn't support OAuth, you can authenticate manually:
Create a
personal API key
using the
MCP Server
preset (this scopes access to a specific project)
Add the
Authorization: Bearer YOUR_API_KEY
header to your MCP configuration
Example for Cursor (add to
.cursor/mcp.json
):
JSON
PostHog AI
{
"mcpServers"
:
{
"posthog"
:
{
"url"
:
"https://mcp.posthog.com/mcp"
,
"headers"
:
{
"Authorization"
:
"Bearer phx_your_api_key_here"
}
}
}
}
Pinning to a specific organization or project
