What is MCP?
The Model Context Protocol (MCP) is a standard that lets LLM-powered tools connect to external services. Instead of being limited to the built-in chat UI, you can use any MCP client to interact with your resumes.Prerequisites
1
Choose your authentication method
Hiresweep MCP supports two authentication methods:
- OAuth2 (recommended): best user experience for clients that support MCP OAuth.
- API key (fallback): works in all clients that can send custom headers.
2
If using API key, create one
Head over to https://hiresweep.com, sign in, and open Settings → Developers → API keys. Select Create API key, give it a name, and copy the key. It’s only shown once.For the full walkthrough, see Using the API.
Configuration
There are two transport options, and each can use either OAuth2 or API key depending on your client capabilities.Method 1: Streamable HTTP (recommended)
If your client supports theurl field (e.g. Cursor, Codex, Claude custom connectors), use this.
Option A: OAuth2 (recommended)
Most OAuth-capable clients only need the MCP URL:Option B: API key (fallback)
If OAuth is not supported in your client, sendx-api-key:
Method 2: mcp-remote
If your client only supportscommand / args (for example, local-only Claude Desktop config), use mcp-remote as a bridge. This requires Node.js 20 or later.
mcp-remote is most commonly used with API keys:
Replace
your-api-key with the API key you created in the prerequisites step.Where to put the config
Authentication details
Hiresweep MCP accepts authentication in this order:- Bearer token (OAuth2 access token) via
Authorization: Bearer <token> - API key fallback via
x-api-key: <key>
401 and advertises OAuth metadata using:
WWW-Authenticate: Bearer resource_metadata="https://hiresweep.com/.well-known/oauth-protected-resource"
OAuth2 flow used by this server
Hiresweep is configured as an OAuth authorization server for MCP clients:- The MCP endpoint is
https://hiresweep.com/mcp. - OAuth discovery metadata is exposed under
/.well-known/*endpoints. - If the user is not signed in, authorization sends them to
/auth/loginand then resumes the OAuth request. - A signed-in user sees a consent screen at
/auth/oauth-consentwith the assistant’s name and every permission it asked for. They tick the permissions it gets and choose Allow or Deny. Deny returnserror=access_deniedto the client. - Hiresweep remembers the grant per user and assistant. A later request for permissions already granted skips the screen; asking for more shows it again.
- PKCE (
S256) is required, and the client, redirect URI, PKCE parameters and session are checked again when the user approves. - Users review and disconnect assistants under Settings → Developers → Connected assistants (see Managing connected assistants). Disconnecting removes the grant and every token the assistant holds, and its current access token stops working on
/mcpat once.
Permissions (OAuth scopes)
Each kind of action is a separate permission. An assistant only sees, and can only call, the tools its permissions cover; calling another tool returns an error that names the missing permission.
A client that asks for no scope gets
resumes:read jobs:read (read-only) plus offline_access. On the consent screen, the permissions that spend credits or cannot be undone start unticked.
API keys are not scoped. A key sent as x-api-key keeps the full access of the account that created it, including applying and deleting. Prefer OAuth for assistants. OAuth access tokens are accepted only on /mcp; the REST and RPC APIs use your session or an API key.
Popular client setup
Cursor
OAuth2 (recommended):Codex (CLI / IDE extension)
Add server:config.toml):
Claude (web app custom connector)
Addhttps://hiresweep.com/mcp as a custom remote MCP connector, then connect with OAuth in Claude’s connector UI.
Claude Desktop (local config file)
Usemcp-remote bridge with API key (example shown above in Method 2).
External references
- Cursor MCP docs
- MCP quickstart for users (Claude Desktop example)
- OpenAI Codex MCP docs
- Claude custom connectors (remote MCP)
- MCP Authorization spec
Available tools
Tool names use canonical unprefixedsnake_case names.
Breaking change (tool names)
Older clients may refer to prefixed or dot-separated names. Those names are no longer registered; update automations and saved prompts to the canonical names above.Available resources
Resources follow MCP conventions: static items appear inresources/list; parameterized access is declared in resources/templates/list and read via resources/read once you know the ID.
Breaking change (schema URI)
The schema resource was previouslyresume://schema. It is now resume://_meta/schema. Update any saved prompts, automations, or client configs that referenced the old URI.
Static server card (/.well-known/mcp/server-card.json)
GET /.well-known/mcp/server-card.json returns a JSON document (SEP-1649) with serverInfo, optional authentication metadata, and summaries of tools, resources, resource templates, and prompts. It is generated to match the live MCP server and can be used for discovery when a client cannot run a full capability scan against /mcp/.
Available prompts
Prompts are pre-built workflows that provide the AI with structured instructions and context. Each prompt embeds the resume data and the schema resource (resume://_meta/schema) automatically.
Usage examples
Once your MCP client is connected, you can use natural language to interact with your resumes:Browsing
- “List my resumes”
- “Show me my resume named ‘Software Engineer’”
- “What skills are listed on my resume?”
- “Show me the stats for my resume”
Creating and managing
- “Create a new resume called ‘Frontend Engineer 2026’”
- “Import this exported ResumeData JSON as a new resume”
- “What tags do I use across my resumes?”
- “Duplicate my ‘Software Engineer’ resume for a product manager role”
- “Make my resume public and give me the share link”
- “Lock my finalized resume so it can’t be accidentally edited”
- “Delete my old draft resume”
Editing
- “Update my name to Jane Doe”
- “Change my headline to Senior Software Engineer”
- “Add TypeScript to my skills with an Advanced proficiency level”
- “Add a new experience entry for my role as Staff Engineer at Acme Corp from Jan 2024 to Present”
- “Remove the third item from my skills section”
Styling
- “Change the template to bronzor”
- “Set the primary color to blue”
- “Hide the interests section”
Using prompts
- “Help me build my resume from scratch” (uses
build_resume) - “Review my resume and give me a score” (uses
review_resume) - “Improve the wording on my resume” (uses
improve_resume)