WebCull
cli

Local MCP

Connect your AI application to WebCull with local MCP tools, separate authorization, and OS keystore protection.

Your Bookmarks In Your Chosen AI Application

WebCull MCP lets a compatible AI application search your bookmarks, browse folders, follow relationships, and make changes you request. It runs on your computer and connects to your WebCull account. There is no hosted MCP server to configure.

CLI and MCP access requires a WebCull subscription or an active subscription trial. Free accounts created through the iOS app do not include this access.

Install And Authorize MCP

Install Node.js 18 or newer, then run these commands in your terminal. Approve only the browser request you just started and choose the intended account.

npm install -g @webcull/cli
webcull mcp login
webcull mcp accounts

MCP signs in separately from the CLI. Signing out of MCP leaves CLI access in place. Account tokens stay in macOS Keychain, Windows Credential Manager, or Linux Secret Service. An unavailable keystore blocks setup; there is no plaintext fallback.

Connect Your AI Application

Run the setup command for your client and copy its configuration object into that client’s MCP settings. The output uses the Node and WebCull paths installed on your computer. Restart the client or reload its MCP servers after saving.

webcull mcp setup --client claude
webcull mcp setup --client vscode

Other local MCP clients can launch webcull with the argument mcp over stdio. Web-only clients that require a remote server URL cannot use this local connection.

Encrypted Accounts: Keystore Setup

For end-to-end encrypted accounts, store your existing encryption passphrase in the OS keystore yourself. Use the account hash shown by webcull mcp accounts. Never paste the passphrase into chat, client configuration, command arguments, or environment variables.

macOS: in Keychain Access, create a password item named webcull-mcp-e2ee, with the account hash as its account name and your encryption passphrase as its password.

Windows: add a Generic Credential in Credential Manager. Use webcull-mcp-e2ee:<account-hash> as the address, the account hash as the username, and your encryption passphrase as the password.

Linux: install secret-tool and run an unlocked Secret Service keyring in the same desktop session as your AI application. Run the command below in an interactive terminal, replace the account hash, and enter the passphrase only at its hidden prompt.

secret-tool store --label='WebCull MCP encryption' service webcull-mcp-e2ee account '<account-hash>'

Check the entry without revealing its contents:

webcull mcp setup --account <account-hash> --check-e2ee

Decryption happens locally, but bookmark text returned by a tool can be sent to your chosen AI provider. Choose fields and accounts accordingly. A missing, locked, or incorrect key stops encrypted operations.

Tools And Everyday Use

MCP covers the same operations as the CLI: account access, limits, bookmark counts, trees, search, retrieval, creation, updates, metadata refresh, graph relationships, and reminder creation, listing, and cancellation. It also includes a setup tool.

Start with webcull_accounts, choose the intended account hash, then pass it as account on every data tool. Ask for a small result first. Only authorize writes you intend, and check the outcome before retrying a write that timed out.

Read the full tool map and troubleshooting guide

Disconnect MCP

webcull mcp logout --account <account-hash>

This revokes MCP access for that account. Your manually stored encryption passphrase remains in the keystore; remove that entry yourself when you no longer need it.

Next step cli Authentication Authorize multiple CLI accounts, select one by hash, verify its identity, and safely log out.