Skip to content

Lanyard

Lanyard is one MCP URL for your agents. Behind it sit the MCP servers you choose, the tools you allow, and each person’s own sign-in to those servers. Your agent gets one endpoint and one key; you keep the choice of what it can reach.

This guide is for people using the Lanyard console. It walks through every screen.

Open Lanyard Get started

Gateways

One MCP URL per gateway, in front of the servers you pick. Create as many as your plan allows.

→ Gateways

Servers and tools

Add servers from the catalog or by URL, then tick exactly which tools agents may call.

→ Servers and tools

Connected accounts

Everyone signs in to each server as themselves. Lanyard holds the token, the agent never sees it.

→ Connected accounts

Keys and agent setup

Mint a key per agent, paste the ready-made config into Claude Code, Cursor, VS Code, Codex or Windsurf.

→ Keys and agent setup

Sharing

Share a gateway with people or with a group from your identity provider, as owner or member.

→ Sharing

Activity

Every tool call and every change, with the outcome, the caller and the key that made it.

→ Activity

Organization settings

Allowed server hosts, your own OAuth clients, every key in the org, and the audit log.

→ Organization settings

Plan and usage

Seats, tool calls against the allowance, rate limits, and billing.

→ Plan and usage

Without one, every agent on every laptop holds its own copy of every token. Rotating a leaked token means finding each machine. Giving somebody a tool they should not have means editing a config file nobody reads.

Lanyard moves all of that to one place:

  • One URL, one key per agent. Revoking a key stops that agent, and only that agent.
  • Tools are opt-in. A server can offer forty tools. Agents see the ones you ticked.
  • Sign-ins are per person. Two people using the same gateway call Jira as themselves, with their own permissions, from their own account.
  • Nothing is shared by accident. A gateway is private until you share it, and org admins set which server hosts are allowed at all.
  1. You create a gateway and add a couple of MCP servers to it.
  2. You pick the tools agents may call, usually starting with the read-only ones.
  3. You connect your own account to each server that needs a sign-in.
  4. You mint a key and paste the config into your agent.
  5. Teammates open the same gateway, connect their own accounts, and mint their own keys.

Start with Getting Started. If you already have a gateway and just want to point an agent at it, skip to Keys and agent setup.