PasserJack help
Connect Gemini CLI
Add PasserJack to Gemini CLI with one command, then start Gemini and finish browser sign-in if prompted.
Signs in through your browser.
Before you start
- A PasserJack account
- Gemini CLI installed
- A terminal on the machine you want to connect
Show the visual walkthrough
Step by step
- Run the add command below in a terminal. --scope user adds PasserJack for every project on this machine.
- Start Gemini CLI. It may start browser sign-in automatically. Keep Gemini running and approve access in a browser on the same computer when prompted.
- Once PasserJack is connected, use its tools. Only if it is not connected and no sign-in is waiting, use the manual sign-in command below inside Gemini CLI, not in your shell. Do not run it after a successful sign-in.
What to paste
gemini mcp add --scope user --transport http passerjack https://passerjack.com/api/mcp
Sign in manually if needed
Skip this if browser sign-in already succeeded.
/mcp auth passerjack
Use an API key instead
Open Agents and API keys, choose Gemini CLI, then expand Use an API key instead to create your key. These examples carry a placeholder.
- No browser on that machine? Open PasserJack, then Settings, then Agents and API keys, choose Gemini CLI, expand Use an API key instead, press Create a key and fill this in, and copy the block. Run that command instead.
gemini mcp add --scope user --transport http passerjack https://passerjack.com/api/mcp -H "Authorization: Bearer pj_paste-your-key-here"
Preview the PasserJack screens

Open Agents and API keys and choose your agent. If you use an API key, each new key is shown exactly once.

This is the screen a browser sign-in lands on. It names the app that is asking and the permissions it wants, and nothing is granted until you approve it. Read covers your whole ordinary Board, including your attachments. The default edit limit protects items the app did not create from changes; it does not hide them from reads.
Check it worked
Ask the agent: who am I connected as?
A correct answer names your account email, the key or app it is using (for example “Grok - Sep 10, 2026”), and its permissions: read, write if granted, and secrets only if you granted it. If it cannot answer, or names a different account, the connection is not made, so go back through the steps.
Granted write access? Ask it to save a short test note, then confirm that note appears on your board.
Vault reads need both secrets permission and an Unlock for agents window you explicitly open in Vault settings. That permission also includes text and extracted details from sensitive Board images without a Vault window. Review the permission and capture boundaries before granting it.
Manage or disconnect
Open PasserJack, then Settings, then Agents and API keys. That page lists your keys, the apps you have connected and your connector credentials, and you revoke any of them from there.
A revoked key stops working immediately. If a client reports an authentication error, check which account it is signed in to and whether its key was revoked before you create another.