Help

Use with your coding agent

Connect a coding agent to your product’s findings so it can use the evidence while editing your code. Its Variantly token only reads findings; it cannot change your report or plan.

Make a token

Open your product's Findings page and find Coding agent access. Name the agent and choose Make a token. The token is shown once; copy it then. A token belongs to one product and can read only that product. Revoke it there at any time.

  • Coding agent access comes with the Starter and Team plans.
  • A product can have three active tokens.
  • A token expires after 90 days. Make a new one.

Connect your agent

The endpoint is https://mcp.variantly.app/api/mcp. Keep the token in an environment variable, here VARIANTLY_TOKEN, not in a file you commit.

Claude Code configuration

Claude Code

claude mcp add --transport http variantly https://mcp.variantly.app/api/mcp \
  --header "Authorization: Bearer $VARIANTLY_TOKEN"
Cursor configuration

Cursor

In .cursor/mcp.json in the project, or ~/.cursor/mcp.json for every project:

{
  "mcpServers": {
    "variantly": {
      "url": "https://mcp.variantly.app/api/mcp",
      "headers": {
        "Authorization": "Bearer ${env:VARIANTLY_TOKEN}"
      }
    }
  }
}
Codex configuration

Codex

In ~/.codex/config.toml:

[mcp_servers.variantly]
url = "https://mcp.variantly.app/api/mcp"
bearer_token_env_var = "VARIANTLY_TOKEN"

Then ask the agent to list the accessibility patterns for the product and fix the first one.

What it can do

The agent gets two tools:

  • list_patterns: the product, its WCAG version and report status, the counts, and each pattern with the criteria it fails and how many places and pages it is on.
  • get_pattern: one pattern in detail. The criteria, the rule, why it matters, how to fix it, and where it occurs (page, selector and an outline of the element), with the next page of places when there are many.

Both read the findings the report claims now. After the agent changes the code, rescan the pages to see whether the finding remains.

Limits

  • The endpoint takes a bearer token only. Clients that need OAuth, such as claude.ai connectors, aren't supported yet.
  • It is read-only.
  • A token can make 60 calls a minute and 5,000 a day. Over that, the answer is 429 with when to retry.
  • A revoked or expired token, or a product whose plan lapsed, is refused on the next call.

What comes from your site is data

Pages, selectors, element outlines, names and messages are copied from the site we scanned, and anyone can write text there. Every such field sits inside an untrusted object and is shortened. The response labels those fields as untrusted and asks the agent to treat them as data. We rebuild an element from its tag, class names and a short list of structural attributes; text, links, titles and free-text attribute values are left out.