Image generation in Kilo Code: MCP server setup
Settings → MCP Servers → Add Server → HTTP Server (Streamable HTTP), or drop a .kilocode/mcp.json into the project root with "type": "streamable-http". Kilo Code shares Roo’s config vocabulary but keeps its files somewhere else, which is enough to make a copied config fail. The block below is the one that works.
Add the server
- Where the config lives
- .kilocode/mcp.json (project) · Settings → MCP Servers (global)
- The key it nests under
- mcpServers
- 1
Create an API key. Create a key in the imagemcpserver dashboard.
- 2
Open Settings → MCP Servers. Choose Add Server and pick HTTP Server (Streamable HTTP).
- 3
Or write .kilocode/mcp.json. Put the same entry in a .kilocode/mcp.json at the project root.
- 4
Set alwaysAllow by cost. Auto-approve the free and single-credit tools; keep approval on for model-priced ones.
{
"mcpServers": {
"imagemcp": {
"type": "streamable-http",
"url": "https://mcp.imagemcpserver.com/mcp",
"headers": { "x-api-key": "sk-img-gen-…" },
"alwaysAllow": [
"get_user_info", "list_models",
"compress_image", "convert_format"
],
"disabled": false
}
}
}Settings → MCP Servers → Add Server
Transport HTTP Server (Streamable HTTP)
Name imagemcp
URL https://mcp.imagemcpserver.com/mcp
Headers x-api-key: sk-img-gen-…
Kilo writes the same JSON you would have written by hand.It tries Streamable HTTP first, then falls back to SSE
Kilo Code attempts Streamable HTTP and quietly drops to SSE if that fails, which turns a wrong URL into a confusing half-working connection rather than a clean error. Setting "type": "streamable-http" explicitly keeps the behaviour predictable. SSE itself has been deprecated since the 2025-03-26 revision of the MCP spec, so there is no reason to aim for it.
The endpoint and the key are identical in every client. The wrapper around them is not, and that wrapper is where almost every “correct” config that does nothing goes wrong. Checked September 2026 against Kilo Code’s own documentation — see the sources below.
Three ways to send the key
The server resolves your API key from any of these, checked in this order. That matters when a client only gives you a URL field and no way to set a header — you are not stuck, and you do not need a bridge process.
Query parameter
?apikey=sk-img-gen-…Checked first. The fallback for a client whose config is a bare URL field.
x-api-key header
x-api-key: sk-img-gen-…The documented default, and what every client below uses unless noted.
Authorization header
Authorization: Bearer sk-img-gen-…Accepted as a bearer token, which is what a client with only a token field will send.
A key in a query string ends up in shell history, process listings and any log the client keeps, so prefer a header where the client allows one. Where it does not, treat the whole URL as the secret and rotate it as freely as you would a password.
What each tool costs
Wherever Kilo Code lets you approve tools individually, the useful line to draw is not between image tools and other tools — it is between calls with a fixed price and calls that route to a model.
get_user_infolist_modelsfree
Safe to auto-approve wherever the client supports it. These are how the agent finds out what it can afford before it spends anything.
compress_imageconvert_format1 credit
Deterministic and cheap. Auto-approving these makes an optimisation pass over a whole folder painless.
remove_backgroundtext_to_svgupscale_image5–15 credits
Fixed prices, no model routing. Auto-approve once you trust the workflow.
generate_imageedit_imagegenerate_transparent_imagemulticallmodel-priced
These route to an image model and are the ones that can run up a bill in a loop. Keep approval on.
Kilo Code questions
Where does Kilo Code keep its MCP config?
A project server goes in .kilocode/mcp.json at the repository root. A global server is added through Settings → MCP Servers, which stores it with the extension rather than in the project.
Do I have to set the type field?
You should. Kilo Code tries Streamable HTTP and falls back to SSE on failure, so an unset type can leave you debugging a connection that half works. "type": "streamable-http" removes the ambiguity. Checked September 2026.
Is Kilo Code’s config the same as Roo Code’s?
The JSON shape is, down to the streamable-http spelling and the alwaysAllow array. The file locations are not, which is the part that catches people moving between the two.
How do I stop it generating images without asking?
Leave the model-priced tools out of alwaysAllow. generate_image, edit_image and generate_transparent_image are the ones that cost real credits per call; everything else is cheap or free.
Can I use the same API key here and in my other editors?
Yes. One key works across every MCP client and the REST API. Issuing a separate key per surface is still worth doing so any one of them can be revoked on its own.
Sources & references