Skip to content

Connect an AI client

Add Tindre as a custom MCP server so an approved client can use governed organizational capabilities.

Tindre exposes permitted organizational capabilities through one remote MCP endpoint. A connection always acts as the person who authorized it, so results follow that person’s access roles and Role visibility.

01

AI client

Connects to the organization’s Tindre MCP address.

02

Person

Signs in with OAuth or supplies a personal access token.

03

Tindre

Filters capabilities and results using live permissions.

Copy the server address

Open Settings → API & MCP and copy the displayed endpoint. It has the form https://<your-tindre-api-host>/mcp. Do not guess the host; a deployment without a configured public address says so.

Choose the client guide

Use the focused setup for Claude, ChatGPT, Cursor, or GitHub Copilot. Any other MCP client follows this page: the address, a credential, and the client's own custom-server settings.

Understand the connection

The MCP server exposes search and call, plus query when the user may search Standards. A missing tool can therefore be a permission decision rather than a broken connection.

Protect governed data

Tool results enter the external client’s context: a capability returns the content itself, not a pointer to it. Approve the provider before rolling this out.

Connection check and common failures

Create credentials for the person or controlled identity that will use the client, then copy the MCP endpoint and credential into the client’s custom server settings. Restart or reconnect the client if it caches its capability list. Ask it to discover Tindre capabilities before requesting a specific action.

An authentication error usually means the credential is missing, expired, or copied incorrectly. A successful connection with fewer capabilities can be correct: Tindre only advertises what the represented identity may use. If search works but a call fails, inspect the chosen capability, its required input, and the caller’s access instead of replacing the credential with a broader one.