o-MATIC

Connect your assistant

The factory's control plane: database, embedder and MCP surface on one host. Point your assistant here and it can read the factory and search the corpus.

Endpointhttps://factory.o-matic.ai/mcpAuth Authorization: Bearer <your token>
Ask your operator for a token. Tokens are issued per client, so one machine can be revoked without disturbing the others. Your laptop and your desktop get different tokens.

Claude Code one command

Paste this in a terminal, replacing the token:

claude mcp add --transport http --scope user omatic-server \
  https://factory.o-matic.ai/mcp \
  --header "Authorization: Bearer YOUR_TOKEN_HERE"

Then restart Claude Code. Verify with claude mcp list.

Keep the token out of the config: put it in ~/.claude/settings.json under "env" as OMATIC_MCP_TOKEN (chmod 600), then use --header 'Authorization: Bearer ${OMATIC_MCP_TOKEN}' with single quotes. The config stores a reference, not a copy, so rotation touches one file.

Codex

[mcp_servers.omatic]
url = "https://factory.o-matic.ai/mcp"
http_headers = { Authorization = "Bearer YOUR_TOKEN_HERE" }

Gemini CLI

In ~/.gemini/settings.json. The field is httpUrl, not url: url selects the deprecated HTTP+SSE transport, which this server does not implement.

{
  "mcpServers": {
    "omatic": {
      "httpUrl": "https://factory.o-matic.ai/mcp",
      "headers": { "Authorization": "Bearer YOUR_TOKEN_HERE" },
      "timeout": 600000
    }
  }
}

Cloud-hosted assistants

This server answers on a public name with a publicly trusted certificate, so an assistant that connects from its vendor’s cloud can reach https://factory.o-matic.ai/mcp. It still needs a credential: a bearer token or this server’s OAuth sign-in. Reachable is not the same as authorized.

Check it works

curl -s https://factory.o-matic.ai/health -H "Authorization: Bearer YOUR_TOKEN_HERE"
curl -s -X POST https://factory.o-matic.ai/mcp -H "Authorization: Bearer YOUR_TOKEN_HERE" \
  -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

/health is private on this server: it answers this host and an authenticated caller, and is 404 to anyone else. If the first command answers with your token and the second returns 401, the server is fine and the second command has a different token.

What you get

startup: grants and the factory state card in one call. search: hybrid semantic + keyword retrieval, embedded on this host so no text leaves it. factory_query: governed SQL against the connections you were granted. task_relationships: which work ties the lanes together. Plus connections_list, embed_query and omatic_guide.