Connecting AI agents (MCP)

Connect Claude Desktop, Cursor, opencode, or any MCP client to your workspace using secure personal access tokens.

The Model Context Protocol (MCP) is the open standard enabling AI agents to interact with external systems. Your workspace serves as an MCP server: once connected, your agents can list overdue tasks, create projects, and retrieve briefings within your authorized scope.

MCP Endpoint
https://weflow-backend-v1-production.up.railway.app/api/mcp

1. Generate an MCP access token

Navigate to Settings › MCP Connections to create a dedicated Personal Access Token (PAT) for your AI agent client.

MCP token management in settings
MCP settings: create secure PAT tokens, select read/write scopes, and review active client connections.
  1. 1

    Click “New Connection”

    Give the connection a descriptive label (“Claude Desktop”, “Cursor”, “opencode”…).

  2. 2

    Select access tier

    Read-only (inspect data) or Read + Write (create and modify tasks and projects).

  3. 3

    Copy your token

    The token (prefixed with wf_live_) is shown only once. It is stored hashed with SHA-256 in the database.

2. Architecture & data flow

MCP flow diagram between AI agent and workspace
MCP flow: the agent discovers available tools from the server and performs actions bounded by your permissions.
MCP access token tiers comparison
Access control: strict boundary enforcement between read-only tokens and write privileges.

3. Configure your AI clients

claude_desktop_config.json
{
  "mcpServers": {
    "omnia": {
      "type": "streamableHttp",
      "url": "https://weflow-backend-v1-production.up.railway.app/api/mcp",
      "headers": {
        "Authorization": "Bearer wf_live_YOUR_TOKEN"
      }
    }
  }
}

4. Security & guardrails

  • Scopes validated on every tool execution — read-only tokens are prevented from writing.
  • Strict tenant isolation — agents only access your organization, never other tenants.
  • Client-side confirmation — write operations prompt for user approval in Claude/Cursor/opencode.
  • Rate limiting — 60 requests/minute per token.
  • Comprehensive audit log — every tool invocation, parameters, and status is recorded.
  • Instant revocation — deleting a token cuts access immediately.