Skip to content

Connecting an AI assistant

An assistant such as Claude or ChatGPT can read your work in ScopeKite and, if you allow it, add to it. It connects to one address, works as you, and can read only what you can already read. Everything it does is recorded under your name.

This page is the long form of Workspace Settings → Assistants, which shows the connector address for your deployment and lets you create tokens. The section appears only where an operator has turned the MCP surface on, and never for guests: owners, admins and members can connect an assistant.

Copy it from Workspace Settings → Assistants. On the staging deployment it is:

https://mcp.scopekite.code.lease/mcp

The address is the identifier every token is bound to. A token minted for one deployment is refused by another, so use the address the settings screen shows rather than one from a different environment.

Use this for assistants that can open a browser window — Claude, ChatGPT, Cursor and others that support remote MCP servers.

  1. In the assistant, add a custom connector. In Claude that is Settings → Connectors → Add custom connector. Other assistants call it a remote MCP server.
  2. Paste the connector address.
  3. ScopeKite opens in your browser. Sign in, pick a workspace if you have more than one, and review what the assistant asks for. Reading is listed apart from adding and editing, so the consequential part is easy to see. You can allow or deny the request as a whole. If it asks for more than you want to give, deny it and use a token instead, where you choose each permission.

Each person connects with their own account. The workspace is chosen during sign-in and bound on the server, not passed by the assistant.

Use this for a terminal, a script, or any client that cannot open a browser.

  1. In Workspace Settings → Assistants, name the token after what it is for and choose what it may do. Reading is always included; adding and editing, and creating projects, are separate checkboxes and off by default.

  2. Copy the token. It is shown once. ScopeKite stores only a hash, so a lost token cannot be recovered — revoke it and create another.

  3. Give it to the client as a bearer header. For Claude Code:

    Terminal window
    claude mcp add --transport http scopekite \
    https://mcp.scopekite.code.lease/mcp \
    --header "Authorization: Bearer YOUR_TOKEN"

    Any other client that can set a header sends Authorization: Bearer YOUR_TOKEN to the same address.

Tokens expire after 90 days. The list in settings shows each token’s name, access, last use and expiry, and Revoke stops one immediately. Treat a token like a password: never paste it into a chat.

Permission What it allows
Read work Your tasks, projects, cycles, comments, members and attachment lists
Read pages Search and read knowledge pages
Add and edit work Create tasks and change them — title, description, assignee, priority, dates, estimate and status
Comment Post comments
Add and edit pages Create pages, revise them, and link them to work
Create projects Start a new project — a separate permission on purpose
Attach files Attach a file to a task (granted through browser sign-in; the token screen does not offer it)

No tool deletes or archives anything, and no tool changes permissions or invites anyone. Edits are checked against the revision the assistant read, so an assistant cannot overwrite a change someone else made in the meantime.

Every call is authorised as you and rate-limited per connection. Each tool call that runs is recorded in the audit trail by tool name and workspace; the arguments — the content of your work — are not recorded.