# MCP

Let your own AI client read and steer your goals through the Auto Lab MCP server, or give any assistant these docs through the public docs server.

Canonical page: https://app.auto-lab.ai/docs/developers/mcp

Auto Lab runs two MCP servers. The first lets an AI client you already use, such as a desktop assistant or a coding tool, read and steer your goals with your permission. The second serves these docs to any assistant, with no sign-in.

| Server | Address | Sign-in | What it reaches |
| --- | --- | --- | --- |
| Auto Lab MCP | `https://api.auto-lab.ai/v1/autolab/mcp` | OAuth, one grant per person | Goals in one organization, under your permissions |
| Docs MCP | `https://app.auto-lab.ai/mcp` | None | Public docs and product pages |

## Connect your AI client to your goals

### Check your client

Your client must support:

- the Streamable HTTP transport;
- OAuth with a client ID you register in advance (automatic client registration is not offered);
- PKCE with the S256 method;
- resource indicators, sending the server address as `resource`;
- a fixed callback URL that you can copy.

The callback must be HTTPS, or HTTP on `localhost`, `127.0.0.1` or `[::1]` for a client that runs on your machine. Auto Lab matches it exactly.

### Register and connect

### Copy the server URL
Open **Personal settings › MCP**. Under **Connect your client**, copy the **Server URL**.

### Register your client
Under **Register a public client**, pick the organization in **Account**. Enter a **Client name** and paste the **Callback URL** your client shows. Leave **Allow project changes and plan approval** off unless the client needs to change things. Select **Register client**, then copy the **Client ID**.

### Sign in from your client
Enter the server URL and the client ID in your client, then start its sign-in. Auto Lab shows a consent page with the organization, the server and the access asked for. Check them, then select **Allow**.

Registering a client needs permission to create OAuth clients in the organization. If you do not have it, ask an organization admin to register the client for you. A registration gives no one access by itself. Each person who uses the client signs in and allows it separately. You need no API key and no client secret.

## What the client can do

The server's tool names say "project" because the API calls a goal a project.

With read access, the client can use:

| Tool | What it returns |
| --- | --- |
| `list_projects` | The goals you can open in the organization you approved. |
| `get_project` | One goal. |
| `get_outcome` | The goal's objective, what it tracks, and its delegation level. |
| `get_plan` | The approved plan. |
| `preview_plan` | A proposed plan in a change request, without approving it. |
| `list_tasks`, `get_task` | The task board, or one task by its key. |
| `list_change_requests` | The goal's change requests. |

With read and write access, it can also use:

| Tool | What it does |
| --- | --- |
| `set_objective` | Save a new objective. It does not re-plan or start work. |
| `create_task` | Add a draft task to the board. It does not start an agent. |
| `update_task` | Move a task to another lane (Planned, Active, Blocked, For review, Done), or change its title or description. |
| `approve_plan` | Approve a plan change request: merge it and queue its first routine. |

Every call runs under your own permissions on that goal, and private session details stay hidden as they do in the app. The grant covers only the organization you approved, even if you belong to others. Lists come in pages: pass `offset` and a `limit` of up to 100.

> **Plan approval starts work**
>
> `approve_plan` merges the plan and can start the goal's routines. Read the plan with `preview_plan` first, and only ask your client to approve it when you mean to. It needs permission to edit the goal, merge its changes and fire its routines. The goal's usual review rules still apply. If an approval reports a failure after the merge, keep the change request ID and retry the same approval once the repository problem is fixed.

## Revoke a client's access

In **Personal settings › MCP**, **Your granted access** lists each client you allowed, marked **Read only** or **Read and change projects**. Select **Revoke** and confirm. The client loses your access and its refresh tokens at once. The client's registration and other people's grants stay in place.

To use the client again, sign in from it and allow it again. Auto Lab never re-approves an MCP client on its own.

## Protocol details

| Topic | Detail |
| --- | --- |
| Transport | Stateless. Send every message as a POST. There are no server sessions or GET event streams. |
| Discovery | Protected-resource metadata at `https://api.auto-lab.ai/.well-known/oauth-protected-resource/v1/autolab/mcp`. It names the Auto Lab authorization server, described in [Sign in with Auto Lab](/docs/developers/api#sign-in-with-auto-lab). |
| Scopes | `mcp:read`, plus `mcp:write` for write access. |
| Resource | The server URL. Send the same value when you ask for a code, exchange it and refresh. |
| Tokens | Access tokens last one hour. Refresh tokens last 30 days and work once each. |
| Credentials | Only tokens from this sign-in work here. Personal access keys and browser sign-ins are refused. |
| Size | A result over 256 KiB returns an error. Ask for a smaller page or one task. |

## Docs MCP

`https://app.auto-lab.ai/mcp` is an anonymous, read-only MCP server with these docs and Auto Lab's public pages. It holds no goal data. Add it to any assistant that supports Streamable HTTP. The exact settings format depends on the assistant, for example:

```json
{
  "mcpServers": {
    "autolab-docs": { "url": "https://app.auto-lab.ai/mcp" }
  }
}
```

| Tool | What it does |
| --- | --- |
| `list_public_content` | List public pages with their title, description and path. Filter with `kind` (`docs`, `marketing`, `blog` or `use-case`) and `limit` (1 to 50, default 25). |
| `get_public_markdown` | Return one page as Markdown, by the path from the list, such as `/docs/quickstart`. |

The server also offers each page as a Markdown resource. Its server card is at `https://app.auto-lab.ai/.well-known/mcp/server-card.json`.

## Plain-text docs for AI tools

Crawlers and assistants that do not speak MCP can read two plain-text files:

| File | What it holds |
| --- | --- |
| `https://app.auto-lab.ai/llms.txt` | An index of the public pages, each linked to its Markdown copy. |
| `https://app.auto-lab.ai/llms-full.txt` | The full text of every public page in one file. |
