Connect an AI client to your workspace over MCP

Your knowledge base and your inbox can be handed to an AI client — Claude Code, Claude Desktop, Cursor — so that "draft an article about our refund policy" or "what did that customer ask on Tuesday" happens where you already work, instead of in a browser tab.

It runs over MCP, the protocol those clients use to reach outside tools. Everything below is on the Integrations page.

First: it is your token, not the workspace's

This is the part worth understanding before you click anything, because it decides what your client can do and who is answerable for it.

Every role can hold one — owner, admin and operator alike. What differs is what the token can then do, which is exactly what that person can do in the console.

Create one

Integrations, then New token. One field: a name, up to 60 characters, seen only by you and your workspace admins.

Name it after the client you will paste it into — "Claude on the laptop", "Cursor at work". Six months from now the list is how you decide which one to revoke, and a list of tokens called "token", "token 2" and "new token" answers nothing.

Then the important part:

The token is shown once. We store only a hash of it, so once you leave that page it cannot be displayed again — not by us either. Copy it before you navigate away.

Lost one? There is no recovery: revoke it and create another. That is a property of storing hashes rather than an inconvenience we could remove.

There is no "rotate" button either, and that is deliberate: rotating is revoke-then-create, two acts you take on purpose, so issuing a second token for a second machine never silently kills the first.

Connect your client

The page gives you the same connection two ways — pick the one your client wants.

Command line. One command to paste in your terminal; Claude Code registers the server itself. This is the shortest path if you use Claude Code.

JSON config. For clients configured by file. The page shows the replium entry to add to whatever is already there:

Add the entry alongside your existing servers rather than replacing the file; these clients hold every MCP server in one object.

What your client can do

Eighteen tools, in four groups. You do not call them by name — you ask in your own words and the client picks — but knowing the shape tells you what is reasonable to ask for.

GroupWhat it coversAn operator's client
ArticlesCreate, read, search (drafts included), rename, re-file, publish, replace the body, mint an image upload link, mint a preview linkRead and search only
CategoriesList the menu, create, rename, move one under anotherList only
ConversationsSearch the inbox, read one thread, reply to the visitor, leave an internal note, transfer, change status or flagAll of it
TeamList teammates — which is what makes "transfer this to Anna" resolvableAll of it

An owner's or admin's client is offered all eighteen; an operator's is offered the ten it can use. That is not cosmetic: the list is what the client plans from, so a tool it cannot use is a promise it might make to you and then fail.

Some things that follow, and are easy to assume wrongly:

What this is good for

The uses that pay off first are the ones where the work is already text and the context is already in the conversation:

When somebody leaves

Two different things stop a client, and which one you use decides whether it stays stopped.

Deactivating the teammate stops their tokens at once — but does not revoke them. Every call resolves the owner and requires them to be active, so from that moment their client fails. Nothing was deleted, though: bring the person back and their tokens work again, with nothing to re-issue and nothing to paste anywhere. That is exactly right for somebody on leave, and exactly wrong for somebody who left.

Revoking is the permanent one. Team tokens on the Integrations page lists every token in the workspace that has not been revoked, with whose it is — including the tokens of people who are already deactivated, since deactivation leaves those rows alone. You cannot see anyone's token there, only revoke it, and a revoked token never works again whatever happens to its owner afterwards.

So: deactivate to stop access now, and revoke as well if you do not want it coming back.

If it stops working

What you seeThe likely reason
The client cannot connect at allThe token was mistyped or truncated — copy it whole, including the rpm_ prefix
It worked yesterday, not todaySomebody revoked that token, or the account it belongs to was deactivated
The client says there is no such toolYour role does not have it. An operator's client is offered ten tools, and the eight authoring ones are not among them
A client that used to write articles suddenly cannotSomebody changed that person's role. The list is decided per call, so a demotion takes effect at once — but a client that already read the old list may report the tool as missing rather than as forbidden