Connecting an AI assistant
An assistant such as Claude or ChatGPT can read your work in ScopeKite and, if you allow it, add to it. It connects to one address, works as you, and can read only what you can already read. Everything it does is recorded under your name.
This page is the long form of Workspace Settings → Assistants, which shows the connector address for your deployment and lets you create tokens. The section appears only where an operator has turned the MCP surface on, and never for guests: owners, admins and members can connect an assistant.
The connector address
Section titled “The connector address”Copy it from Workspace Settings → Assistants. On the staging deployment it is:
https://mcp.scopekite.code.lease/mcpThe address is the identifier every token is bound to. A token minted for one deployment is refused by another, so use the address the settings screen shows rather than one from a different environment.
Connect with your browser
Section titled “Connect with your browser”Use this for assistants that can open a browser window — Claude, ChatGPT, Cursor and others that support remote MCP servers.
- In the assistant, add a custom connector. In Claude that is Settings → Connectors → Add custom connector. Other assistants call it a remote MCP server.
- Paste the connector address.
- ScopeKite opens in your browser. Sign in, pick a workspace if you have more than one, and review what the assistant asks for. Reading is listed apart from adding and editing, so the consequential part is easy to see. You can allow or deny the request as a whole. If it asks for more than you want to give, deny it and use a token instead, where you choose each permission.
Each person connects with their own account. The workspace is chosen during sign-in and bound on the server, not passed by the assistant.
Connect with a token
Section titled “Connect with a token”Use this for a terminal, a script, or any client that cannot open a browser.
-
In Workspace Settings → Assistants, name the token after what it is for and choose what it may do. Reading is always included; adding and editing, and creating projects, are separate checkboxes and off by default.
-
Copy the token. It is shown once. ScopeKite stores only a hash, so a lost token cannot be recovered — revoke it and create another.
-
Give it to the client as a bearer header. For Claude Code:
Terminal window claude mcp add --transport http scopekite \https://mcp.scopekite.code.lease/mcp \--header "Authorization: Bearer YOUR_TOKEN"Any other client that can set a header sends
Authorization: Bearer YOUR_TOKENto the same address.
Tokens expire after 90 days. The list in settings shows each token’s name, access, last use and expiry, and Revoke stops one immediately. Treat a token like a password: never paste it into a chat.
What an assistant can do
Section titled “What an assistant can do”| Permission | What it allows |
|---|---|
| Read work | Your tasks, projects, cycles, comments, members and attachment lists |
| Read pages | Search and read knowledge pages |
| Add and edit work | Create tasks and change them — title, description, assignee, priority, dates, estimate and status |
| Comment | Post comments |
| Add and edit pages | Create pages, revise them, and link them to work |
| Create projects | Start a new project — a separate permission on purpose |
| Attach files | Attach a file to a task (granted through browser sign-in; the token screen does not offer it) |
No tool deletes or archives anything, and no tool changes permissions or invites anyone. Edits are checked against the revision the assistant read, so an assistant cannot overwrite a change someone else made in the meantime.
What ScopeKite keeps
Section titled “What ScopeKite keeps”Every call is authorised as you and rate-limited per connection. Each tool call that runs is recorded in the audit trail by tool name and workspace; the arguments — the content of your work — are not recorded.