It does not just look at your flags — it changes them.
Authorising this is a browser sign-in rather than a key: the hosted server uses OAuth, so there is no API token to generate, paste or rotate.
The login you authorise with sets the ceiling. If its role is not allowed to create and delete flags, the connection breaks just after the consent screen instead of during it.
What authorising it lets it see.
every flag in the projects that login can reach, and what each is serving right now
the prompts and model choices a shipped AI feature runs on
logs, traces and grouped errors coming off a live product
the dashboards built on top of those
And what it can alter.
make a flag, and destroy one
switch a flag on or off, and rewrite who it applies to
add a prompt configuration, edit it, or delete it outright
Whatever that role is barred from, this is barred from too — down to individual projects and environments.
Two deployments do not have this server at all: accounts on LaunchDarkly's federal or European Union instances have to run the local one instead.
Its full tool list, and how each editor hooks up to it:LaunchDarkly MCP
https://mcp.launchdarkly.com/mcp/launchdarkly