Setup guide

Connect your own AI key and an MCP client

Bring your own provider key so AI features run on your account instead of a shared one, and connect an external app to read and update your Trakwyn data directly. Both are optional, and both are set up from inside the product once you're signed in.

Part 1 — Bring your own AI key

What BYOK means

Trakwyn's AI features — parsing job descriptions, drafting cover letters, matching your resume to a role, company briefings, and the chat assistant — call out to a large language model. With BYOK, that call uses an API key you generate on your own account with a provider like OpenAI or Anthropic, instead of a key Trakwyn manages for everyone.

Where the cost lands

Usage is billed by the provider straight to your own account — Trakwyn never sees the charge and adds nothing on top. Check your provider's pricing page for per-request cost.

How your key is stored

Your key is encrypted at rest and only decrypted on the server, in the moment it's needed to make a request on your behalf. It's never sent to your browser after you save it, and never shown again — if you lose track of it, remove it and add it again.

Add a provider key

  1. Create a key with your chosen provider — see the note below the tabs for where.
  2. Sign in to Trakwyn and go to Settings → AI.
  3. Paste in the key and save. The model field is optional for every provider except a custom endpoint, where it — and a base URL — are both required.

Create a key at openrouter.ai/keys.

What to expect the first time

Today a key is only checked for the right shape when you save it, not tested against the provider. If it's wrong, expired, or out of credit, you'll find out the first time you use an AI feature, not at save time — that's what the error will mean if one shows up.


Part 2 — Connect an MCP client

What MCP exposes

The Model Context Protocol lets an outside app — Claude Desktop, Cursor, or anything that speaks MCP — read your job-search data and, if you allow it, create or update it too. Nothing ever deletes: there are no delete tools at all.

Read tools

Applications, notes, interview rounds, contacts, work history, skills, documents, offers, activity, calendar, analytics.

Write tools — Full access only

Create or update applications, notes, interview rounds, skills, education, and work experience.

Connect with OAuth

Recommended

The easiest way to connect a client — nothing to copy, paste, or manage. If your client supports OAuth, just point it at Trakwyn and it handles the rest:

  1. In your client, add Trakwyn as a remote MCP server using the server URL below.
  2. The client opens a sign-in window — sign in with your existing Trakwyn account, no separate step.
  3. Approve the consent screen, choosing Read-only or Full access — start with Read-only unless the client genuinely needs to create or update records.
  4. Done — the client is connected. Nothing to copy, and nothing to lose track of.
https://api.trakwyn.com/mcp

Revoking is all-or-nothing: taking back access from a client (below, or from within the client itself) invalidates everything that consent ever issued it, so it can't quietly refresh its way back in.

Manage connected clients

Every client you've approved over OAuth is listed in Settings → Integrations, alongside your API tokens, where you can revoke access at any time.

Client configs

Claude Desktop / Cursor — add as a remote server

{
  "mcpServers": {
    "trakwyn": { "url": "https://api.trakwyn.com/mcp" }
  }
}

The client opens a browser to sign in and consent the first time it connects — the exact key name may vary slightly by client version, so check its docs if this doesn't match.

Claude Code

claude mcp add --transport http trakwyn https://api.trakwyn.com/mcp

Advanced: connect with an API token

For a script, a CI job, or a client that doesn't support OAuth — a long-lived token you paste into its config yourself.

  1. Sign in and go to Settings → Integrations.
  2. Name the token so you remember what it's for.
  3. Choose a scope — start with Read-only unless it genuinely needs to create or update records. A read-only token is refused by both the write tools and the API itself, so it can't change anything even if it leaks.
  4. Copy the token — it's shown once, right after you create it.

Generic JSON-RPC, with the token on the header

curl -s https://api.trakwyn.com/mcp \
  -H "Authorization: Bearer trakwyn_your_token_here" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

New to Trakwyn? Start free and set this up in minutes.

Get started for free