A repo-level mcp.json can list the server name, command, and sample paths. Put real tokens in the user env or the OS keychain.
Document which env vars are required next to the file. Do not paste a working production key into chat.
If two people need the same SaaS, prefer a shared read-only bot account over copying a personal OAuth session.
Pair this with MCP env secrets and OAuth basics. Rotate anything that ever landed in a screenshot.