Docs menu

Get started

Install LexLint in Claude Code

One plugin carries the skill, three commands and the server, on the desktop and in cloud sessions.

Two commands: add the marketplace, then install the plugin from it.

claude plugin marketplace add ungovr/lexlint
claude plugin install lexlint@lexlint

Install the plugin. It carries the whole client: the lexlint skill that runs the loop, the /lexlint, /lexlint-key and /lexlint-feedback commands, and mcp.lexlint.io already configured. The bundle holds no executables: one skill, three commands, and the schema, all of them readable before you run anything.

Restart your session afterwards. Plugins load at process start, and a /clear is not a restart. Then run /lexlint in any repository.

No key yet? Run /lexlint-key: it hands you a sign-in link for a free one, takes the key you paste back, and puts it where your next session will read it: on Claude Code that is the env block of your user settings file, chmod 600, and never a file that gets committed. The plugin reads the value from UNGOVR_API_KEY at process start rather than holding a copy of its own, so the key is never written into the server registration, and a key exported into an already-running session is read by nothing.

On Claude Code for the web, install from the repository

A cloud session at https://claude.ai/code has no terminal to type the command into, and /plugin is one of the commands that only runs in the terminal. So the repository carries the install instead. Commit this as .claude/settings.json and every cloud session on that repository starts with LexLint already installed:

{ "extraKnownMarketplaces": { "lexlint": { "source": { "source": "github", "repo": "ungovr/lexlint" } } }, "enabledPlugins": { "lexlint@lexlint": true } }

Then open the cloud environment's network access and add mcp.lexlint.io to its allowed domains. This is the step to get right, because skipping it fails late rather than loudly: the default access tier reaches GitHub, which is why the marketplace fetch above succeeds, but it does not reach us, so the plugin installs cleanly and then every tool call cannot connect. A custom allowlist with this one host added is enough; opening the environment to any domain is not necessary.

Set UNGOVR_API_KEY as an environment variable on that same cloud environment. Each session copies those values into ordinary environment variables at startup, which is where the plugin's server configuration reads the key from. If it is missing, nothing breaks silently: check_access still answers and reports the key as absent, and every other tool refuses with the sign-in link and the steps attached to the refusal.

Committing a project .mcp.json works too, and registers the server on its own without the skill or the commands. Worth knowing that a cloud session cannot show the trust prompt a terminal session shows for project servers, so it loads them without asking. The same three settings apply to a session started from the desktop app or an IDE extension, which otherwise behave like the CLI.

Or the tools on their own, without the plugin

This registers the server and nothing else: no skill, no commands, and no lexlint.yml loop. Keep the single quotes: they leave ${UNGOVR_API_KEY:-} for Claude Code to fill in each time it connects, so the key is read from your environment and never written into the config. With no key yet the header goes out empty, which is enough to connect, and check_access then names the ways to get one.

claude mcp add --transport http -s user lexlint \ https://mcp.lexlint.io/mcp \ --header 'X-API-Key: ${UNGOVR_API_KEY:-}'

The header is the part that matters. Registered with no X-API-Key header at all, the server answers with a sign-in challenge, and sign-in is not open to new clients yet, so /mcp shows the server as needing authentication and lists no tools. Remove that entry and add it again with the header.