What you can do
Answer questions about access
Ask who is in the workspace, who holds the owner role, or whether a given address already has an account.
Onboard new members
Invite someone and grant them roles in specific neeto products in a single request.
Offboard people who leave
Deactivate a member and end their sessions across every neeto product at once.
Hand off the busywork
Ask your assistant to onboard a new hire from an offer letter, or find and deactivate everyone who left last quarter.
MCP vs CLI: which should I use?
NeetoAuth’s CLI reaches the same resources MCP does - workspace members and products. Two gaps are small:ListUsers filters by an email substring and the CLI has no flag for that, but the CLI’s --quiet output piped through jq narrows the same list; and the CLI can enable or disable a product, which MCP cannot. Otherwise, neither one can do more than the other, so choose on how the work reaches NeetoAuth.
Reach for MCP when
- The details live in your chat, not in your head. An offer letter, a Slack thread, or a pasted IT ticket turns into the invitation, with no retyping. The CLI cannot see any of it.
- You have not decided the steps yet. “These contractors finished last week - make sure they are out” means looking at what is there and choosing. A command can only carry out a decision you have already made.
- One request should cover several steps. Find out which products the workspace has and what roles each one exposes, invite the person with those grants, then read back the grants the server resolved, with no glue between commands.
- The person doing it does not use a terminal. NeetoAuth hosts the server, so there is nothing to install or keep updated.
Reach for the CLI instead when
- No AI assistant should be in the loop. A cron entry or a CI step runs the CLI with nothing but the binary and a workspace it is already signed in to - no assistant open, no model account, no tokens spent per run. Every MCP call needs something with model access running.
- The output feeds another program. The CLI prints a bare identifier or raw JSON for
jq, a spreadsheet, or your own script. Here you get prose you would have to copy out by hand. - You are working through thousands of records. Here every page is a separate tool call, and a member list that long crowds out the assistant’s context. The CLI returns
total_pagesnext to the records, so a shell loop walks every page unattended and writes each one to a file or intojq- the size of the workspace stops mattering. - The run has to be repeatable and reviewable. A command is the artifact: it records exactly what ran and repeats identically. Ask twice here and the assistant may take a different route.
What you need
- An AI assistant that supports MCP, such as Claude, ChatGPT, Claude Code, Codex, Cursor, Gemini CLI, VS Code with GitHub Copilot, Windsurf, or Antigravity.
- A NeetoAuth account. You need an API key only if the assistant must reach the whole workspace, or if you use Antigravity. See Authentication.