Docs menu
Get started
Quickstart Install: Claude Code Install: Codex Install: other clients API keysConcepts
How a run works The app profile The severity model What a run does not sayTools
check_access claim_trial_key set_profile run_lint get_law resolve_domain_jurisdiction submit_feedback upload_lint_runGuides
A whole run, end to end Console TestPack in CIReference
Endpoint and transport lexlint.yml schema Errors ChangelogHelp
Support and feedbackGet started
Install LexLint in Claude Code
One plugin carries the skill, three commands and the server, on the desktop and in cloud sessions.
Two commands: add the marketplace, then install the plugin from it.
claude plugin marketplace add ungovr/lexlint
claude plugin install lexlint@lexlint
Install the plugin. It carries the whole client: the lexlint skill that
runs the loop, the /lexlint, /lexlint-key and
/lexlint-feedback commands, and mcp.lexlint.io already configured. The
bundle holds no executables: one skill, three commands, and the schema, all of them
readable before you run anything.
Restart your session afterwards. Plugins load at process start, and a /clear
is not a restart. Then run /lexlint in any repository.
No key yet? Run /lexlint-key: it hands you
a sign-in link for a free one, takes the
key you paste back, and puts it where your next session will read it: on Claude Code
that is the env block of your user settings file, chmod 600, and never a
file that gets committed. The plugin reads the value from UNGOVR_API_KEY at
process start rather than holding a copy of its own, so the key is never written into
the server registration, and a key exported into an already-running session is read
by nothing.
On Claude Code for the web, install from the repository
A cloud session at https://claude.ai/code has no
terminal to type the command into, and /plugin is one of the commands
that only runs in the terminal. So the repository carries the install instead. Commit
this as .claude/settings.json and every cloud session on that repository
starts with LexLint already installed:
Then open the cloud environment's network access and add
mcp.lexlint.io to its allowed domains. This is the step to get right,
because skipping it fails late rather than loudly: the default access tier reaches
GitHub, which is why the marketplace fetch above succeeds, but it does not reach us,
so the plugin installs cleanly and then every tool call cannot connect. A custom
allowlist with this one host added is enough; opening the environment to any domain
is not necessary.
Set UNGOVR_API_KEY as an environment variable on that same cloud
environment. Each session copies those values into ordinary environment variables at
startup, which is where the plugin's server configuration reads the key from. If it
is missing, nothing breaks silently: check_access still answers and
reports the key as absent, and every other tool refuses with the sign-in link and the
steps attached to the refusal.
Committing a project .mcp.json works too, and registers the server on its
own without the skill or the commands. Worth knowing that a cloud session cannot show
the trust prompt a terminal session shows for project servers, so it loads them
without asking. The same three settings apply to a session started from the desktop
app or an IDE extension, which otherwise behave like the CLI.
Or the tools on their own, without the plugin
This registers the server and nothing else: no skill, no commands, and no
lexlint.yml loop. Keep the single quotes: they leave
${UNGOVR_API_KEY:-} for Claude Code to fill in each time it connects, so
the key is read from your environment and never written into the config. With no key
yet the header goes out empty, which is enough to connect, and
check_access then names the ways to get one.
The header is the part that matters. Registered with no X-API-Key header
at all, the server answers with a sign-in challenge, and sign-in is not open to new
clients yet, so /mcp shows the server as needing authentication and lists
no tools. Remove that entry and add it again with the header.