← All documentation

Connect Integral

MCP server

Last updated: September 28, 2026

Integral speaks the Model Context Protocol, so an AI client you already use can work inside your workspace: search the knowledge base, read and write documents, run workflows and agents, pull reports and tables, and — for admins — manage connectors, people, settings and spend.

It is one endpoint and one rule: the client acts as the member who authorised it, and can never do more than that person could do in the app. There is no service account and no workspace-wide key.

The endpoint

URL
https://integral.meteorit.rs/api/mcp
Transport
Streamable HTTP, protocol revision 2025-06-18
Authentication
OAuth 2.1 with dynamic client registration and PKCE, or an mk_ API key sent as a bearer token
Discovery
/.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server
Sessions
None. Every request re-resolves its credential, so a revoked grant is dead on the next call rather than at the end of a TTL.
Workspace
The credential names it. If you belong to two workspaces, you connect twice.

Setting it up

Every client below points at the same URL. Prefer OAuth wherever the client offers a Connect button: it binds the grant to you, shows you a consent screen, and can be revoked from either side.

Claude — web, desktop, and Cowork

One connector list, shared across all three. Add it once.

  1. 1In Claude, open Settings → Connectors → Add custom connector, and paste the endpoint.
    https://integral.meteorit.rs/api/mcp
  2. 2Claude registers itself and sends you to Integral. Sign in if you are not already.
  3. 3The consent screen names the workspace, you as the acting member, and the permissions being requested. Approve, and the tools appear in the client.

Claude Code

Add it once for a project, or with --scope user for every project.

  1. 1Add the server from the terminal:
    claude mcp add --transport http integral https://integral.meteorit.rs/api/mcp
  2. 2Run /mcp inside a session and choose Authenticate. The browser opens the same consent screen.
    /mcp

Cursor, Windsurf, and other config-file clients

Remote MCP over HTTP; the client opens the OAuth flow on first use.

  1. 1Add the server to the client’s MCP config — in Cursor that is ~/.cursor/mcp.json:
    {
      "mcpServers": {
        "integral": {
          "url": "https://integral.meteorit.rs/api/mcp"
        }
      }
    }
  2. 2Reload the client and approve the consent screen when it opens.

Grok and Grok Bot

A custom connector on grok.com; a custom MCP server in Grok Bot. The Grok article has the full steps.

  1. 1On grok.com open Connectors → New Connector → Custom and paste the endpoint. In Grok Bot, ask the bot to add a custom MCP server with the same URL.
    https://integral.meteorit.rs/api/mcp
  2. 2Sign in to Integral and approve the consent screen.

Scripts, CI, and anything without a Connect button

Use an API key. It is bound to one member and one workspace, exactly like a grant.

  1. 1An admin mints the key in Settings → API keys, choosing its permissions and expiry. It is shown once.
  2. 2Send it as a bearer token to the same endpoint:
    Authorization: Bearer mk_…

What a client may do

Three rings decide every call, and the result is never wider than the narrowest: what you may do in the workspace, what the credential was granted, and what the tool itself allows. A viewer holding a write permission still cannot write.

Permissions are grouped the way the app is, and you approve them per group on the consent screen:

  • —Assistant — ask the workspace assistant, search the knowledge base
  • —Documents, Reports, Tables, Dashboard — read, and write where you already can
  • —Workflows and Agents — read, run, and edit
  • —Connectors — see what is connected, and manage it (admins)
  • —People, Workspace, Costs, Audit — team, settings, spend caps and the audit trail (admins)

What the workspace controls

  • Every grant is visible and killable. Settings → API keys → Connected clients lists every connected client, who owns it and when it was last used, with per-row revoke. Admins see all of them; you see yours.
  • Deactivating a person revokes their clients. Access is re-read from their live membership on every request, so there is no cleanup step to forget.
  • An admin can switch member connections off entirely. With it off, only admins may connect a client, and the consent screen says so instead of failing vaguely.
  • Consequential actions ask a person. Anything that sends, deletes or spends returns a confirmation link instead of acting, and a human approves it.
  • Rate and spend limits are per credential. Over the rate limit you get a 429 with Retry-After; past the credential’s monthly budget or the workspace cap, a 402.

When it does not work

  • 401 on every call. The grant was revoked, the key expired, or the membership was deactivated. They answer identically on purpose — reconnect the client.
  • A tool is missing rather than failing. Your role does not reach it. Role-gated tools are removed from the list entirely, so a client never offers something that would then be refused.
  • 403 with a missing permission. The credential was granted less than the tool needs. Reconnect and approve that group, or ask an admin to mint the key with it.
  • The Connect button refuses. Member connections are switched off for the workspace. An admin turns them back on in workspace settings.