> ## Documentation Index
> Fetch the complete documentation index at: https://docs.get-hive.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Hive MCP server: use Hive from Claude, Cursor and other AI clients

> Connect Claude, Cursor, VS Code or any MCP client to Hive's remote MCP server, sign in with OAuth, and use Hive's product actions as tools.

Hive runs a **remote Model Context Protocol (MCP) server**. Point an MCP client — Claude Code,
Claude.ai, Claude Desktop, Cursor, VS Code or any other client that speaks MCP — at it, sign in,
and your AI assistant can work in Hive on your behalf: read signals, answer from the Business
Brain, run workflows and agents, search the Library, and take the other actions you can take in
the app.

There is nothing to install or host. The server uses the **Streamable HTTP** transport, and you
sign in with your normal Hive account.

<Info>
  This page is about AI clients connecting **to** Hive. For the opposite direction — Hive connecting
  to another tool's MCP server — see [Connect MCP servers](/integrations/mcp-servers).
</Info>

## Your server URL

If your workspace's **Settings → Connected AI clients** shows the MCP server URL, the server is
available to you — copy the URL from there. It is:

```text theme={null}
https://mcp.get-hive.ai/mcp
```

Use the URL from Settings if it differs from the example.

## Connect your client

<Tabs>
  <Tab title="Claude Code">
    ```bash theme={null}
    claude mcp add --transport http hive https://mcp.get-hive.ai/mcp
    ```

    Then run `/mcp` in Claude Code and choose **hive** to sign in.
  </Tab>

  <Tab title="Claude.ai and Claude Desktop">
    Open **Settings → Connectors → Add custom connector**, paste the server URL and save. Claude
    opens the Hive sign-in page the first time you connect.
  </Tab>

  <Tab title="Cursor, VS Code and others">
    Add Hive to your client's MCP configuration:

    ```json theme={null}
    {
      "mcpServers": {
        "hive": {
          "url": "https://mcp.get-hive.ai/mcp"
        }
      }
    }
    ```

    The client opens the Hive sign-in page when it first connects.
  </Tab>
</Tabs>

Clients register themselves automatically, by OAuth dynamic client registration or a client ID
metadata document, so you never create a client ID or secret by hand.

## Sign in and consent

<Steps>
  <Step title="Your client opens Hive">
    The client sends you to a Hive consent page in your browser. Sign in if you are not already
    signed in.
  </Step>

  <Step title="Check who is asking">
    The page shows the client's name, where you will be sent back to, the workspace it will act in,
    and the access it asks for. A client that registered itself automatically is labelled
    **unverified**: its name is whatever it chose to call itself, so judge it by where you will be
    sent back. If that is not a place you expect, deny the request.
  </Step>

  <Step title="Choose the access">
    The page lists the access the client asked for, area by area — see [Access by
    area](#access-by-area). You can narrow it to any part of that request, for example read-only, or
    a single area. You can never grant more than the client asked for. A client that asks for
    nothing specific gets read-only access to all areas.
  </Step>

  <Step title="Return to your client">
    Approve, and Hive sends you back to the client, which can now call Hive's tools.
  </Step>
</Steps>

You sign in the same way you sign in to Hive, including any single sign-on or social login your
workspace uses. Sign-in uses **OAuth 2.1 with PKCE** through Hive's authorization server at
`https://oauth.get-hive.ai`. Your client never sees your Hive password or session.

## Access by area

Access is granted per product area. **Read** lets the client see what you can already see in
that area; **Write** lets it take the actions you are already allowed to take there, and includes
**Read** for the same area. Your role still applies on top: access you grant never lets a client
do more than you can do in the app.

| Area | Read | Write |
| - | - | - |
| **Ask chats** | `chats:read` — Read your Ask conversations, projects, comments, attachments, generated documents and the models Ask can use. | `chats:write` — Ask questions (uses model credit); create, rename, move or delete conversations, projects, comments and documents; import documents from, or save them to, a connected drive. |
| **Library & prompts** | `library:read` — Browse the Library folders, files and templates you can access, and your saved prompts. | `library:write` — Upload, edit, move, share and delete Library files, folders and templates, and manage saved prompts. |
| **Business Brain** | `brain:read` — Read what Hive knows about your business: facts, baselines, relationships and entities such as customers, suppliers and people. | `brain:write` — Add, correct or delete Brain facts and relationships, edit entities, and confirm website-onboarding facts. |
| **Signals, inbox & insights** | `signals:read` — Read signals, signal cases, the owner inbox, monitoring, the activity feed, daily brief and the health, impact, value and maturity reports. | `signals:write` — Dismiss, snooze, mute and plan signals, run signal-case commands, mark inbox items handled, and change monitoring (can use model credit). |
| **Agent Studio** | `agents:read` — Read agents, their revisions, sharing, schedules, runs and results. | `agents:write` — Create, edit, deploy, share, schedule, run, cancel and delete agents. Runs use model credit and can read connected sources. |
| **Workflows & schedules** | `workflows:read` — Read workflows, their versions, runs, templates, builder chats, schedules and scheduled tasks. | `workflows:write` — Create, edit, publish, share, schedule, run, cancel and delete workflows. Running a workflow carries out its steps in connected tools, such as sending messages or updating records. |
| **Diligence & company overviews** | `diligence:read` — Read diligence and company-overview projects, tasks, knowledge, runs and generated artifacts, including confidential data-room material. | `diligence:write` — Create and run projects (uses model credit), upload data rooms and templates, approve KPIs and narratives, change diligence policy and delete projects. |
| **Approvals & actions** | `approvals:read` — Read pending and past approval requests. | `approvals:write` — Approve or reject actions, act on a signal and start an inbox scan — Hive then carries them out in connected tools, for example sending an email or message. |
| **Autonomy & automations** | `autonomy:read` — Read action types, autonomy and spend-cap policy, learned automation rules, active automations and the kill-switch state. | `autonomy:write` — Change what Hive may do without asking: autonomy levels, promotion rules, spend caps, learned rules, connector autonomy, automations and the kill switch. |
| **Connectors & channels** | `connectors:read` — Read connected apps, the connector and MCP-server catalog, connector settings, incoming webhooks and Slack/Teams installations. | `connectors:write` — Sync, configure and disconnect connectors, MCP servers and channel installations, and manage incoming webhooks. Connecting a new account stays in the Hive app. |
| **Members, groups & access** | `members:read` — Read the member list, groups, the product access policy and who can access a given item. | `members:write` — Manage groups, the product access policy and item access grants. Inviting, re-roling or removing members stays in the Hive app. |
| **Workspace settings** | `settings:read` — Read workspace configuration: general settings, branding, chat rules, usage limits, sharing policy, models, skill packs and the onboarding program. | `settings:write` — Change workspace-wide configuration that affects every member, including allowed and custom models, skill packs and data-sharing consent. |
| **Plan & billing** | `billing:read` — Read the plan, seats, credits, invoices and billing account details. | `billing:write` — Request quotes, preview seat changes, and request or withdraw a seat. Payments, subscriptions, top-ups and credentials stay in the Hive app. |
| **Audit log & usage analytics** | `audit:read` — Read the workspace audit log and per-member usage analytics. | Read-only: no write access. |
| **Your account** | `account:read` — Read your own identity, personal settings, notifications, onboarding checklist and the personal memories Hive keeps about you. | `account:write` — Change your personal memories, mark notifications read and record your onboarding progress. |

Two more options cover every area at once, including areas Hive adds later:

* **All areas (read)** — `hive:read`.
* **All areas (write)** — `hive:write`, which includes `hive:read`.

A few actions reach across areas, such as undoing an audited action, so they need **All areas
(write)**. Acting on a signal and starting an inbox scan fall under **Approvals & actions**.

Developers configuring a client request these as OAuth scopes, space separated — for example
`signals:read workflows:write`. `find_tools` and your client's tool list only show the tools your
connection can use.

## What your client can do

Hive's product actions are available as MCP tools — Signals, Inbox, Business Brain, Ask,
Workflows, Agent Studio, Library, Company Overview, Diligence, settings and the rest of the
product. When Hive adds a product action, it appears as a tool automatically. Tool names start
with the area they act on, such as `signals_list` and `signals_snooze`.

Some things stay in the Hive app and are never tools, whatever access you grant:

* payments, subscriptions, credit top-ups, seat assignment, and changes to your own model
  provider keys (reading your plan and requesting a seat are tools);
* creating incoming webhooks, because the new signing secret would pass through the AI model;
* inviting members, changing their roles, and removing them;
* Hive staff platform tools;
* managing AI client connections and consent;
* connecting accounts to Hive (OAuth sign-in with your tools);
* public agent links;
* live event streams and test utilities.

A tool never lets you do more than you can do in the app. The same approvals, autonomy levels
and receipts apply — see [Review and approve](/approvals/review-and-approve).

### Toolsets

| Toolset | URL | What your client sees |
| - | - | - |
| Full (default) | `…/mcp` | Every tool your access allows, plus `find_tools`. |
| Search | `…/mcp?toolset=search` | Only `find_tools` and `call_tool`. |

* **`find_tools`** — describe what you want in plain language, such as "snooze a signal". Hive
  ranks its tools by meaning and by keyword and returns the best matches with their input
  schemas.
* **`call_tool`** — in the search toolset, run a tool by name with its arguments.

Use `?toolset=search` with clients that limit how many tools they can load. In the search
toolset, `call_tool` runs **read-only tools only**. Actions that change data need the full
toolset, so your client lists each one as its own tool and can ask you to approve every call.

## Security

* **Short-lived access.** Access tokens last 10 minutes and only work against the Hive MCP
  server. Your client refreshes them in the background.
* **Rotating refresh tokens.** Every refresh issues a new refresh token. If an old one is used
  again, Hive treats it as stolen and revokes the whole connection.
* **Connections expire.** A connection ends after 14 days without use, and after 90 days at
  most however often it is used. Sign in again to reconnect.
* **Permissions are checked on every call.** Your role and workspace permissions apply to each
  tool call, not just at sign-in, so a role change applies from your client's next call. If you
  are removed from the workspace, or your membership is revoked, your AI client connections end
  when they next refresh.
* **No staff elevation.** Hive staff platform access never applies over MCP.
* **Limits apply.** Tool calls are rate-limited per connection, and your plan's limits apply
  exactly as they do in the app.

## Manage connected clients

**Settings → Connected AI clients** lists each client you have connected, with:

* the client's name and the host it returns to,
* the areas it can read or change,
* when it was connected, last used, and when it expires.

Revoke a client to disconnect it straight away. Owners and Admins can also see and revoke
every member's connections in the workspace.

## Related

<CardGroup cols={2}>
  <Card title="Connect MCP servers" icon="server" href="/integrations/mcp-servers">
    The other direction: Hive using another tool's MCP server.
  </Card>

  <Card title="Roles and permissions" icon="user-shield" href="/admin/roles-and-permissions">
    What each role can see and do — and so what a connected client can.
  </Card>

  <Card title="Security overview" icon="lock" href="/security/overview">
    How Hive isolates workspaces and protects access.
  </Card>

  <Card title="Developer overview" icon="code" href="/developers/overview">
    Every way to build on Hive.
  </Card>
</CardGroup>
