Streamable HTTP at https://sahnga.com/mcp. Same personal access token as the REST API. The MCP handler validates the token and calls the internal services directly — it never forwards that token to /api/v1.
Mint a token in account settings— pick the workspace and what the token may view or edit. The workspace is bound in token metadata, never encoded in the secret. Then drop this into Cursor's mcp.json:
{
"mcpServers": {
"sahnga": {
"url": "https://sahnga.com/mcp",
"headers": {
"Authorization": "Bearer sng_YOUR_TOKEN"
}
}
}
}Tools
whoamiToken name, grants, bound workspace ids. No workspaceId.
list_projectsProjects the token owner can see.
list_tasksTasks in a project.
get_taskOne task by id.
search_tasksTitle prefix search.
create_taskCreate a task. Requires tasks.create.
update_taskUpdate a task. Requires tasks.update.
list_commentsComments on a task. Requires comments.view.
add_commentComment on a task. Requires comments.create.
my_tasksTasks assigned to you.
Sahnga still ships no chatbot and never trains on workspace data. Writes show as the token name. Omit workspaceId when the token is bound to one workspace. Call whoami if you are unsure.