1. Try the sandbox
Run:/mcp to inspect the connection.
The sandbox needs no Plainrouter account or key, returns synthetic data, and never contacts Meta. Ask:
sandbox: true. This checks the connection, not production data or ad execution.
2. Create a workspace key
In Plainrouter, select your workspace and open Settings → Workspace keys. Create a Read key for analysis; use Write for Actions, including Actions record reads. Copy it once into your protected credential configuration. Each key covers one workspace. Never put keys in prompts or source control. Key permissions and replacement.3. Add Plainrouter to the client
Merge this entry into~/.gemini/settings.json, preserving other settings:
PLAINROUTER_WORKSPACE_KEY through your local secret manager in the environment that starts Gemini CLI. Leave the variable reference in the file. Restart the client, check /mcp, and select plainrouter for production reads.
4. Verify the connection
Start with this read-only request:5. Troubleshooting
- Disconnected: use
httpUrlor--transport http;urlconfigures the older SSE transport. - Tools appear but calls return 401: discovery can be public. Confirm the key variable is available to the client and has not expired or been revoked.
- Wrong server is used: keep distinct
plainrouter-testandplainrouternames and name the intended one in your request.