Skip to main content
Hive runs a remote Model Context Protocol (MCP) server. Point an MCP client — Claude Code, Claude.ai, Claude Desktop, Cursor, VS Code or any other client that speaks MCP — at it, sign in, and your AI assistant can work in Hive on your behalf: read signals, answer from the Business Brain, run workflows and agents, search the Library, and take the other actions you can take in the app. There is nothing to install or host. The server uses the Streamable HTTP transport, and you sign in with your normal Hive account.
This page is about AI clients connecting to Hive. For the opposite direction — Hive connecting to another tool’s MCP server — see Connect MCP servers.

Your server URL

If your workspace’s Settings → Connected AI clients shows the MCP server URL, the server is available to you — copy the URL from there. It is:
Use the URL from Settings if it differs from the example.

Connect your client

Then run /mcp in Claude Code and choose hive to sign in.
Clients register themselves automatically, by OAuth dynamic client registration or a client ID metadata document, so you never create a client ID or secret by hand.
1

Your client opens Hive

The client sends you to a Hive consent page in your browser. Sign in if you are not already signed in.
2

Check who is asking

The page shows the client’s name, where you will be sent back to, the workspace it will act in, and the access it asks for. A client that registered itself automatically is labelled unverified: its name is whatever it chose to call itself, so judge it by where you will be sent back. If that is not a place you expect, deny the request.
3

Choose the access

The page lists the access the client asked for, area by area — see Access by area. You can narrow it to any part of that request, for example read-only, or a single area. You can never grant more than the client asked for. A client that asks for nothing specific gets read-only access to all areas.
4

Return to your client

Approve, and Hive sends you back to the client, which can now call Hive’s tools.
You sign in the same way you sign in to Hive, including any single sign-on or social login your workspace uses. Sign-in uses OAuth 2.1 with PKCE through Hive’s authorization server at https://oauth.get-hive.ai. Your client never sees your Hive password or session.

Access by area

Access is granted per product area. Read lets the client see what you can already see in that area; Write lets it take the actions you are already allowed to take there, and includes Read for the same area. Your role still applies on top: access you grant never lets a client do more than you can do in the app. Two more options cover every area at once, including areas Hive adds later:
  • All areas (read) — hive:read.
  • All areas (write) — hive:write, which includes hive:read.
A few actions reach across areas, such as undoing an audited action, so they need All areas (write). Acting on a signal and starting an inbox scan fall under Approvals & actions. Developers configuring a client request these as OAuth scopes, space separated — for example signals:read workflows:write. find_tools and your client’s tool list only show the tools your connection can use.

What your client can do

Hive’s product actions are available as MCP tools — Signals, Inbox, Business Brain, Ask, Workflows, Agent Studio, Library, Company Overview, Diligence, settings and the rest of the product. When Hive adds a product action, it appears as a tool automatically. Tool names start with the area they act on, such as signals_list and signals_snooze. Some things stay in the Hive app and are never tools, whatever access you grant:
  • payments, subscriptions, credit top-ups, seat assignment, and changes to your own model provider keys (reading your plan and requesting a seat are tools);
  • creating incoming webhooks, because the new signing secret would pass through the AI model;
  • inviting members, changing their roles, and removing them;
  • Hive staff platform tools;
  • managing AI client connections and consent;
  • connecting accounts to Hive (OAuth sign-in with your tools);
  • public agent links;
  • live event streams and test utilities.
A tool never lets you do more than you can do in the app. The same approvals, autonomy levels and receipts apply — see Review and approve.

Toolsets

  • find_tools — describe what you want in plain language, such as “snooze a signal”. Hive ranks its tools by meaning and by keyword and returns the best matches with their input schemas.
  • call_tool — in the search toolset, run a tool by name with its arguments.
Use ?toolset=search with clients that limit how many tools they can load. In the search toolset, call_tool runs read-only tools only. Actions that change data need the full toolset, so your client lists each one as its own tool and can ask you to approve every call.

Security

  • Short-lived access. Access tokens last 10 minutes and only work against the Hive MCP server. Your client refreshes them in the background.
  • Rotating refresh tokens. Every refresh issues a new refresh token. If an old one is used again, Hive treats it as stolen and revokes the whole connection.
  • Connections expire. A connection ends after 14 days without use, and after 90 days at most however often it is used. Sign in again to reconnect.
  • Permissions are checked on every call. Your role and workspace permissions apply to each tool call, not just at sign-in, so a role change applies from your client’s next call. If you are removed from the workspace, or your membership is revoked, your AI client connections end when they next refresh.
  • No staff elevation. Hive staff platform access never applies over MCP.
  • Limits apply. Tool calls are rate-limited per connection, and your plan’s limits apply exactly as they do in the app.

Manage connected clients

Settings → Connected AI clients lists each client you have connected, with:
  • the client’s name and the host it returns to,
  • the areas it can read or change,
  • when it was connected, last used, and when it expires.
Revoke a client to disconnect it straight away. Owners and Admins can also see and revoke every member’s connections in the workspace.

Connect MCP servers

The other direction: Hive using another tool’s MCP server.

Roles and permissions

What each role can see and do — and so what a connected client can.

Security overview

How Hive isolates workspaces and protects access.

Developer overview

Every way to build on Hive.