What is MCP?
The Model Context Protocol (MCP) is a standard that lets LLM-powered tools connect to external services. Instead of being limited to the built-in chat UI, you can use any MCP client to interact with your resumes.Prerequisites
1
Choose your authentication method
Reactive Resume MCP supports two authentication methods:
- OAuth2 (recommended): best user experience for clients that support MCP OAuth.
- API key (fallback): works in all clients that can send custom headers.
2
If using API key, create one
Head over to https://rxresu.me (or your self-hosted instance), sign in, and navigate to Settings → API Keys. Click Create a new API key, give it a name, and copy the secret. It is shown only once.For the full walkthrough, see Using the API.
Configuration
There are two transport options, and each can use either OAuth2 or API key depending on your client capabilities.Method 1: Streamable HTTP (recommended)
If your client supports theurl field (e.g. Cursor, Codex, Claude custom connectors), use this.
Option A: OAuth2 (recommended)
Most OAuth-capable clients only need the MCP URL:Option B: API key (fallback)
If OAuth is not supported in your client, sendx-api-key:
Method 2: mcp-remote
If your client only supportscommand / args (for example, local-only Claude Desktop config), use mcp-remote as a bridge. This requires Node.js 20 or later.
mcp-remote is most commonly used with API keys:
Replace
your-api-key with the API key you created in the prerequisites step.Where to put the config
Authentication details (how Reactive Resume MCP works)
Reactive Resume MCP accepts authentication in this order:- Bearer token (OAuth2 access token) via
Authorization: Bearer <token> - API key fallback via
x-api-key: <key>
401 and advertises OAuth metadata using:
WWW-Authenticate: Bearer resource_metadata="<instance>/.well-known/oauth-protected-resource"
OAuth2 flow used by this server
Reactive Resume is configured as an OAuth authorization server for MCP clients:- The MCP endpoint is
https://rxresu.me/mcp. - OAuth discovery metadata is exposed under
/.well-known/*endpoints. - The login/authorization route is
/api/auth/oauth. - If the user is not signed in,
/api/auth/oauthredirects to/auth/login, then resumes OAuth. - If the user is signed in,
/api/auth/oauthuses the OAuth provider to validate the signed request, registered redirect URI, scopes, resource grants, and PKCE before issuing an authorization code, and redirects back to the client. - PKCE parameters (
code_challenge,code_challenge_method) are preserved in the authorization flow.
Popular client setup
Cursor
OAuth2 (recommended):Codex (CLI / IDE extension)
Add server:config.toml):
Claude (web app custom connector)
Addhttps://rxresu.me/mcp as a custom remote MCP connector, then connect with OAuth in Claude’s connector UI.
Claude Desktop (local config file)
Usemcp-remote bridge with API key (example shown above in Method 2).
External references
- Cursor MCP docs
- MCP quickstart for users (Claude Desktop example)
- OpenAI Codex MCP docs
- Claude custom connectors (remote MCP)
- MCP Authorization spec
Self-hosting
If you’re running a self-hosted Reactive Resume instance, replacehttps://rxresu.me/mcp with your instance URL:
Reconnecting after the OAuth provider upgrade
Self-hosted instances automatically apply the additive OAuth schema migration at startup. This preserves existing client and token records and adds the provider’s resource and client-resource tables. Clients registered before OAuth provider 1.7 do not have per-resource grants. Remove the old connection from your MCP client and add it again so it dynamically registers a new client, then sign in again. Refreshing an existing token does not create these grants. New registrations receive only the resources configured for this instance; existing clients are not automatically granted access.Available tools
Tool names use canonical unprefixedsnake_case names.
Breaking change (tool names)
Older clients may refer to prefixed or dot-separated names. Those names are no longer registered; update automations and saved prompts to the canonical names above.Available resources
Resources follow MCP conventions: static items appear inresources/list; parameterized access is declared in resources/templates/list and read via resources/read once you know the ID.
Breaking change (schema URI)
The schema resource was previouslyresume://schema. It is now resume://_meta/schema. Update any saved prompts, automations, or client configs that referenced the old URI.
Static server card (/.well-known/mcp/server-card.json)
GET /.well-known/mcp/server-card.json returns a JSON document (SEP-1649) with serverInfo, optional authentication metadata, and summaries of tools, resources, resource templates, and prompts. It is generated to match the live MCP server, and a client that cannot run a full capability scan against /mcp/ can use it for discovery.
Available prompts
Prompts are pre-built workflows that give the AI structured instructions and context. Each prompt embeds the resume data and the schema resource (resume://_meta/schema) automatically.
Usage examples
Once your MCP client is connected, you can work with your resumes in natural language:Browsing
- “List my resumes”
- “Show me my resume named ‘Software Engineer’”
- “What skills are listed on my resume?”
- “Show me the stats for my resume”
Tracking applications
- “Create an application for Senior Frontend Engineer at Acme, stage saved, source LinkedIn.”
- “List my archived applications tagged remote.”
- “Move my Acme application to interview and add a note that the technical screen is next Tuesday.”
- “Attach this resume PDF to the Acme application.”
- “Score the resume linked to this application against the job description.”
- “Create a tailored resume copy for this application.”
- “Draft a follow-up message for the recruiter.”
Creating and managing
- “Create a new resume called ‘Frontend Engineer 2026’”
- “Import this exported ResumeData JSON as a new resume”
- “What tags do I use across my resumes?”
- “Duplicate my ‘Software Engineer’ resume for a product manager role”
- “Make my resume public and give me the share link”
- “Lock my finalized resume so it can’t be accidentally edited”
- “Delete my old draft resume”
- “Download a PDF of my Software Engineer resume”
- “Download the visible cover letter from my Software Engineer resume as a PDF”
Editing
- “Update my name to Jane Doe”
- “Change my headline to Senior Software Engineer”
- “Add TypeScript to my skills with an Advanced proficiency level”
- “Add a new experience entry for my role as Staff Engineer at Acme Corp from Jan 2024 to Present”
- “Remove the third item from my skills section”
Styling
- “Change the template to bronzor”
- “Set the primary color to blue”
- “Hide the interests section”
Using prompts
- “Help me build my resume from scratch” (uses
build_resume) - “Review my resume and give me a score” (uses
review_resume) - “Improve the wording on my resume” (uses
improve_resume)