Your account, your permissions
MCP authenticates to Bench with your account or a scoped Bench API key. A client cannot use MCP to bypass repository access, tenant isolation, key limits, or evaluation quotas. Prefer hosted sign-in when your client supports it. For a local server or automation, create a key on the MCP page in Bench. Keys are shown once. Keep them in personal client configuration or a secret manager, not in a repository, prompt, screenshot, or chat.Local environments
Use theBENCH_API_BASE_URL supplied by the environment that created your key. A local key will not authenticate against the production API. Do not copy production credentials into a test account.
Actions with consequences
Ask your coding agent to get confirmation before spending evaluations or creating pull requests. A reviewable candidate is not an applied, deployed, or independently validated fix.