{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-mcp/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Connect an AI client","projectTitle":"Scytale Developer Portal","description":"Programmatic access to your Scytale compliance data."},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"connect-an-ai-client","__idx":0},"children":["Connect an AI client"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Scytale runs a hosted ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://modelcontextprotocol.io"},"children":["MCP"]}," server that gives"," ","AI agents ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["read-only"]}," access to your compliance data — the same controls,"," ","audits, policies, monitors, vendors, people and risks you see in the app. Point"," ","Claude, Claude Code, ChatGPT or Codex at the URL below, sign in as a Scytale"," ","admin, and the agent can answer questions from your live data."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The server cannot change anything in Scytale. Every tool it exposes reads;"," ","none writes."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"mcp-url","__idx":1},"children":["MCP URL"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Region"},"children":["Region"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"MCP URL"},"children":["MCP URL"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["US"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.scytale.ai/mcp/v1"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["EU"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.eu.scytale.ai/mcp/v1"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the host your Scytale data lives in. Note that the US host carries no"," ","region segment. Examples on this page use the US URL — substitute your own."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The server speaks MCP over ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Streamable HTTP"]},". It is hosted by Scytale in each"," ","region; there is no self-hosted or local version."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":2},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A Scytale account with the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["admin"]}," role in the company you want to"," ","connect. Other roles cannot authorize a client, and neither can Scytale"," ","support acting on your behalf."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["One of the supported clients: ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Claude"]}," (web and desktop), ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Claude Code"]},","," ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ChatGPT"]}," (web) or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Codex"]}," (CLI, IDE extension, or Codex inside the"," ","ChatGPT desktop app). These are the only clients Scytale's authorization"," ","server accepts today; any other MCP client is refused with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["invalid_client"]}," ","before sign-in starts."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["ChatGPT and Codex are two different connection paths, even though both come"," ","from OpenAI. ChatGPT connects through its ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Apps"]}," settings; Codex connects"," ","through its own MCP configuration and CLI. Setting up one does not set up the"," ","other."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The URL is all you need. There is no API key, client ID or secret to create"," ","or paste — the client discovers Scytale's authorization server from the URL"," ","and completes sign-in in your browser."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"connect","__idx":3},"children":["Connect"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"claude-web-and-desktop","__idx":4},"children":["Claude (web and desktop)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Custom connectors are available on every Claude plan. The desktop app and"," ","claude.ai share the same connector list, so you add it once."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["On a Free, Pro or Max plan"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Free accounts can add one custom connector."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Customize → Connectors"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+"]}," and choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add custom connector"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Paste your MCP URL, for example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.scytale.ai/mcp/v1"]},". Leave"," ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Advanced settings"]}," empty — Scytale does not use a client ID or secret."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},", then ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connect"]}," and follow the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#authorize"},"children":["authorization"]}," ","steps."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In a conversation, open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+"]}," menu → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connectors"]}," and switch Scytale"," ","on."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["On a Team or Enterprise plan"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["An organization ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Owner"]}," adds the connector once; everyone else connects to"," ","it individually."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Owner:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Organization settings → Connectors"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},", hover over ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Custom"]}," and choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Web"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Paste the MCP URL. Leave ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Advanced settings"]}," empty."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Each member:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Customize → Connectors"]}," and find the Scytale connector."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connect"]}," and follow the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#authorize"},"children":["authorization"]}," steps. Each"," ","person signs in with their own Scytale admin account and picks their own"," ","company."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"claude-code","__idx":5},"children":["Claude Code"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Add the server, then authorize it:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"claude mcp add --transport http scytale https://api.scytale.ai/mcp/v1\nclaude mcp login scytale\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude mcp login"]}," opens your browser for the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#authorize"},"children":["authorization"]}," ","steps. You can also run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/mcp"]}," inside a Claude Code session, pick ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["scytale"]}," ","and choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authenticate"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["By default the server is registered for the current project only. To make it"," ","available in every project, add ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["--scope user"]},":"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"claude mcp add --transport http --scope user scytale https://api.scytale.ai/mcp/v1\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To check the connection, run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude mcp list"]}," — Scytale should show as"," ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connected"]},". To switch company or sign in again, run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude mcp logout scytale"]}," (or choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Clear authentication"]}," in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/mcp"]},") and then"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude mcp login scytale"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"chatgpt-web","__idx":6},"children":["ChatGPT (web)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["ChatGPT connects to Scytale as a custom MCP app. Before you start:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["You need a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Plus, Pro, Business, Enterprise or Edu"]}," plan. Free accounts"," ","cannot add custom apps."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Developer mode"]}," must be on: open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Apps"]}," (shown as ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Apps &"," ","Connectors"]}," in some accounts), scroll to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Advanced settings"]}," and switch"," ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Developer mode"]}," on."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On a Business, Enterprise or Edu workspace, a workspace ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["owner or admin"]}," ","must allow custom apps before the option appears for members."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Then create the app:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Apps"]}," and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a name, for example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Scytale"]},", and a short description."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Paste your MCP URL, for example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.scytale.ai/mcp/v1"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authentication"]},", choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth"]},". Leave any client ID or client"," ","secret field empty - Scytale does not use them."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},". ChatGPT opens a window for the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#authorize"},"children":["authorization"]}," ","steps: sign in to Scytale, choose a company, approve the read access. When"," ","the window closes, ChatGPT scans the server for its tools."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In a conversation, open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+"]}," menu, choose the Scytale app, and ask"," ","your question. Apps added in Developer mode are enabled per conversation,"," ","so pick it again in a new chat or name it in your prompt."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This is the path for regular ChatGPT conversations in the browser. It does not"," ","configure Codex; for the Codex CLI, IDE extension or Codex inside the ChatGPT"," ","desktop app, follow the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#codex"},"children":["Codex"]}," section below."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"codex","__idx":7},"children":["Codex"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This section applies to the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Codex CLI"]},", the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Codex IDE extension"]}," and"," ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Codex inside the ChatGPT desktop app"]},". All three read the same configuration,"," ","so you set the server up once and it is available in all three. It does not"," ","connect Scytale to regular ChatGPT conversations - for those, use"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#chatgpt-web"},"children":["ChatGPT (web)"]}," above. Add the server, then sign in:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"codex mcp add scytale --url https://api.scytale.ai/mcp/v1\ncodex mcp login scytale --scopes read:controls,read:audits,read:policies,read:monitors,read:vendors,read:people,read:risks\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Pass the permissions explicitly, as above. Codex takes its default permissions"," ","from the authorization server's metadata rather than from the MCP server's,"," ","and a plain ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp login scytale"]}," can end in a connection that looks"," ","signed in but holds no Scytale permission: the consent screen lists nothing,"," ","Codex reports success, and every tool call then fails with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Auth required"]},"."," ","The explicit list is always safe and matches what the consent screen shows."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp login"]}," opens your browser for the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#authorize"},"children":["authorization"]}," ","steps. The server is saved to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["~/.codex/config.toml"]},":"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"toml","header":{"controls":{"copy":{}}},"source":"[mcp_servers.scytale]\nurl = \"https://api.scytale.ai/mcp/v1\"\n","lang":"toml"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["No ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["bearer_token_env_var"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http_headers"]}," entry is needed; OAuth is Codex's"," ","default for HTTP servers. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp login"]}," keeps the credential it obtains"," ","outside this file, so the entry stays as shown. To check the connection, run"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp list"]},". To switch company or sign in again, run"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp remove scytale"]},", then add the server and log in again."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"authorize","__idx":8},"children":["Authorize"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The first time a client calls the server it is answered with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401"]}," and sent"," ","to Scytale to sign you in. What you see in the browser:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sign in to Scytale"]}," with your usual account, if you are not already"," ","signed in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Choose a company."]}," Only companies where you are an admin are listed."," ","If you belong to one company, it is the only option."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Approve"]}," the read permissions the client is asking for."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The browser returns you to the client and the connection completes."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"one-company-per-connection","__idx":9},"children":["One company per connection"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The access the client receives is tied to the company you chose. It cannot see"," ","another company's data, even if you administer several. To work with a"," ","different company, disconnect or clear the client's authentication and connect"," ","again, choosing the other company."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"session-lifetime","__idx":10},"children":["Session lifetime"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Access is granted in short-lived tokens that the client renews in the"," ","background, so you do not sign in on every use. A connection lasts ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["40 days"]}," ","from the moment you authorized it; after that the next call fails with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401"]}," ","and you go through the authorization steps again."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"verify-the-connection","__idx":11},"children":["Verify the connection"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Check the connection in two steps, in this order, so a failure points at one"," ","cause:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Test the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ping"]}," tool."]}," Ask the agent something like \"Use the Scytale"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ping"]}," tool with the message hello\". A reply that echoes the message proves"," ","the client reaches the server and holds a valid session. From the command"," ","line, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude mcp list"]}," (Claude Code) or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp list"]}," (Codex) shows the"," ","same thing: Scytale listed as connected."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Make a real read-only request."]}," Ask for data you know exists, for"," ","example \"List my audits\" (the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_audits"]}," tool). A result from your own"," ","company proves the whole path: OAuth succeeded, the connection is bound to"," ","the right company, and the permissions you approved reach the data."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If step 1 works and step 2 fails, the connection is fine and the problem is"," ","permissions or company scope - see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#troubleshooting"},"children":["Troubleshooting"]},". If"," ","step 1 fails, start from the URL and the authorization steps."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-you-can-access","__idx":12},"children":["What you can access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After connecting, the client lists the tools below. Every one of them reads"," ","data; there are no create, update or delete tools. The list shown by your"," ","client is authoritative — it grows as Scytale adds coverage."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Area"},"children":["Area"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Tools"},"children":["Tools"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"What they return"},"children":["What they return"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Controls"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_controls"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_control"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your control set with owner, applicability, framework mapping and linked monitors. Filter by audit, owner or applicability."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Controls"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["find_open_audit_items"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The controls currently blocking an audit, oldest first, with a status summary."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Audits"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_audits"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_audit"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Each audit's framework, status and period."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Policies"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_policies"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_policy"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your policies and where each stands on sign-off."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Monitors"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_monitors"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_monitor"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The automated and manual checks behind your controls, with their current status."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Vendors"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_vendors"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_vendor"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your third parties and their risk posture."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["People"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_people"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_person"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The people in scope for your compliance program, with employment status, job title and hire and termination dates."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Risks"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_risks"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_risk"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your risk register: likelihood and impact scores, the asset at risk, and the mitigation plan and its status."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Connectivity"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ping"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Echoes a message. Useful to confirm the connection works before asking real questions."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Each ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_*"]}," list tool returns pages of results; the agent pages through them"," ","for you. The single-item tools take an ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["id"]}," from a list result. A list tool"," ","accepts the same filters as its endpoint in the"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/openapi"},"children":["API reference"]}," — ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["employmentStatus"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["source"]}," on"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_people"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mitigationStatus"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mitigationPlan"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ownerId"]}," on"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_risks"]},", and so on — and the tool's own description, shown by your client,"," ","lists them too."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"security-and-scope","__idx":13},"children":["Security and scope"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Read-only."]}," The server exposes no tool that can create, change or delete"," ","anything in Scytale, and no such tool can be enabled."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Admin-only."]}," Only company admins can authorize a client. The consent"," ","screen offers only the companies you administer; there is no way to grant"," ","access to any other."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Company-scoped."]}," Each connection is bound to the one company chosen at"," ","sign-in. Switching companies means authorizing again."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Short-lived access."]}," Access tokens expire after 30 minutes and are renewed"," ","by the client in the background; they are never shown to you."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No shared secrets."]}," There is no API key or client secret to leak, rotate"," ","or revoke. Disconnecting the client discards its copy of the credentials;"," ","there is not yet a way to revoke a connection from inside Scytale, and a"," ","connection that is not disconnected lapses 40 days after it was authorized."," ","To cut off an existing connection, remove the user's admin role in that"," ","company or deactivate the user: the client's next token renewal, within 30"," ","minutes, is refused."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Standard OAuth 2.1"]}," with PKCE over TLS. Scytale runs the authorization"," ","server; sign-in never happens inside the AI client."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Your organization decides."]}," In Claude Team and Enterprise plans only an"," ","Owner can add a custom connector, so Scytale is available to members only if"," ","an Owner chose to add it."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"troubleshooting","__idx":14},"children":["Troubleshooting"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Symptom"},"children":["Symptom"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Cause"},"children":["Cause"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"What to do"},"children":["What to do"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ChatGPT shows no ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]}," button or no custom app option under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Apps"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Developer mode is off, the account is on a Free plan, or the workspace owner has not allowed custom apps"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Switch on ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Developer mode"]}," under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Apps → Advanced settings"]},"; on a Business, Enterprise or Edu workspace, ask a workspace owner or admin to allow custom apps"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ChatGPT's OAuth window fails, or the tool scan after sign-in fails"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The URL is wrong or the wrong region, the browser blocked the popup, your account is not an admin of any company, or sign-in finished in a different browser than the one ChatGPT opened"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Check the URL against the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#mcp-url"},"children":["table above"]},", allow popups for chatgpt.com, finish sign-in in the same browser, then delete the app and create it again"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ChatGPT lists the Scytale app but does not use it in a chat"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Apps added in Developer mode are enabled per conversation"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Select Scytale from the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+"]}," menu in that conversation, or name it in your prompt"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Codex reports ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Successfully logged in"]}," but lists no tools, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp list"]}," shows the server as not logged in, or calls fail with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Auth required"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The login requested no Scytale permission, so the token it holds grants nothing"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp remove scytale"]},", add the server again and log in with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["--scopes"]}," command in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#codex"},"children":["Codex"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401"]}," / ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Needs authentication"]}," / client reports the server is unauthorized"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["No session yet, or the connection passed its 40-day lifetime"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Run the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#authorize"},"children":["authorization"]}," steps again — ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude mcp login scytale"]}," in Claude Code, the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["codex mcp login"]}," command with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["--scopes"]}," in Codex"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Sign-in works but the company you want is not offered, or authorization ends in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["access denied"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your account is not an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["admin"]}," of that company"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Ask a company admin to connect, or have your role changed and try again"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The agent answers about the wrong company"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The connection is bound to a different company than you expected"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Clear the client's authentication and connect again, choosing the right company"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A tool returns ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["not_found"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["id"]}," is wrong, or belongs to a company other than the one this connection is bound to"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Take the id from a fresh list result, such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_controls"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["get_audits"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A tool returns ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["bad_request"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A filter value the tool does not accept, for example a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["source"]}," none of your people came from"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Check the values in the tool's description and try again"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The client reports ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["invalid_client"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The client is not one Scytale's authorization server accepts"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Connect from Claude, Claude Code or Codex"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The client asks for a client ID, secret or API key"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Optional credential fields in the client, such as Claude's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Advanced settings"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Leave them empty. There are no credentials to enter"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["No browser opens and the connection fails immediately"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The URL is wrong: missing ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/mcp/v1"]},", or the wrong region"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Check the URL against the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#mcp-url"},"children":["table above"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Claude says it cannot reach the server"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Claude connectors require a server reachable from the public internet; a VPN or proxy on your side may be interfering"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Retry without the VPN or proxy"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A long request ends with a connection error"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Responses that stay idle for more than 60 seconds are dropped"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Narrow the request — filter by audit, owner or status instead of asking for everything"]}]}]}]}]}]},"headings":[{"value":"Connect an AI client","id":"connect-an-ai-client","depth":1},{"value":"MCP URL","id":"mcp-url","depth":2},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"Connect","id":"connect","depth":2},{"value":"Claude (web and desktop)","id":"claude-web-and-desktop","depth":3},{"value":"Claude Code","id":"claude-code","depth":3},{"value":"ChatGPT (web)","id":"chatgpt-web","depth":3},{"value":"Codex","id":"codex","depth":3},{"value":"Authorize","id":"authorize","depth":2},{"value":"One company per connection","id":"one-company-per-connection","depth":3},{"value":"Session lifetime","id":"session-lifetime","depth":3},{"value":"Verify the connection","id":"verify-the-connection","depth":2},{"value":"What you can access","id":"what-you-can-access","depth":2},{"value":"Security and scope","id":"security-and-scope","depth":2},{"value":"Troubleshooting","id":"troubleshooting","depth":2}],"frontmatter":{"seo":{"title":"Connect an AI client"}},"lastModified":"2026-10-08T10:10:30.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/mcp/custom-connector","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}