Publish to Hub
Hub is optional. It exists for one thing: keeping accepted operating state — and a persistent MCP endpoint — reachable while every machine you own is switched off. Everything on this page is a deliberate, explicit step. Nothing here happens automatically.
Hub is an invite-only alpha. Signing in is open to anyone, but creating or using Hub resources requires an invite. If you sign in and every call returns
beta_access_required, that is the allowlist, not a bug.
1. Point mcue at the Hub
mcue hub set https://api.mcue.dev
This verifies the origin and stores it. mcue hub status shows the current
configuration and your linked-project cursors at any time.
2. Log in
mcue login
This opens your browser and runs OAuth authorization code with PKCE. mcue is a
public client with no embedded secret; the refresh credential lands in your OS
credential store — Keychain on macOS, Credential Manager on Windows, Secret
Service on Linux. Tokens never touch project files, $MCUE_HOME, logs, or shell
history.
Confirm it worked:
mcue whoami
3. Publish a project
mcue publish payments-api
Publishing:
- creates a private Hub project with a server-generated UUID,
- validates and submits your current state as an idempotent baseline import,
- stores only the Hub project UUID, device id, and sync cursor locally,
- prints the stable MCP endpoint and how to connect it.
Your source repository is not sent. Only governed operating state is.
The baseline upload accepts at most 500 files and 5 MiB of governed state.
A local project already above that size cannot connect to the Hub through
mcue publish today: the command refuses with the limit named, and uploads
nothing rather than part of the project. Lifting that ceiling needs both an
upgraded Hub and an upgraded CLI; an installed CLI older than the release that
carries it still refuses to capture a project above the budget, including for
incremental sync. Never delete history to fit an upload. See
large-project recovery limits.
Publish several at once, or everything:
mcue publish payments-api ledger-svc
mcue publish --all
4. Connect the hosted MCP endpoint
The endpoint is stable and the same for every project you publish:
https://api.mcue.dev/mcp
Project selection comes from tool arguments and your authorised membership, not from a per-project URL. Connect it once and it covers everything you publish afterwards.
You do not need the CLI to connect. Claude.ai, ChatGPT, Claude Code, and Cursor each take the URL and run the sign-in in your browser — the per-client steps are in Connecting a client to the hosted endpoint.
A client you connect can read and write your own projects. You signed it in on your own account, so there is no separate step to allow saves. To narrow one, restrict it to read or revoke it in the Hub connection settings at hub.mcue.dev. A restricted client that tries to write gets a clear refusal rather than a confusing permission error.
5. Verify
mcue sync status payments-api
No network request — it reads your local cursor and outbox. A freshly published project should show a cursor and zero pending operations.
Cloning onto a second machine
Install mcue, point it at the same Hub, log in, then:
mcue clone payments-api
That materialises the Hub project into local state. From there both machines are replicas of the same ordering — see Work offline and sync.
Unpublishing, and what it does not do
mcue unlink payments-api
unlink removes only this machine's Hub link and pending outbox. Your local
project state stays. The Hub project stays. Other machines stay linked.
Deleting the hosted project, exporting it, and deleting your account are browser-only operations in the Hub UI — they require an authenticated session and typed confirmation, and no OAuth client can perform them on your behalf.
What Hub can and cannot see
- Can see: operating state you explicitly published — checkpoints, decisions, plans, lane state — plus device records, client grants, and the technical metadata needed to run the service.
- Cannot see: your source repository, anything in a project you have not published, or any project state on a machine that has not synced.
Related
- Authority and conflicts — what publishing changes about who decides ordering.
- MCP tools — the surface the hosted endpoint exposes.