Apiboo documentation

DocsSecurity & AI

MCP Server

Let Claude Code, Codex, Cursor and Claude Desktop work with your Apiboo data, with your permission.

Apiboo has a built-in MCP server. MCP (Model Context Protocol) is how AI tools such as Claude Code, Codex, Cursor and Claude Desktop talk to other programs. With it, an agent can read your documents and boards, plan on your calendar, build requests in your collections and, only if you allow it, run commands on your servers.

Nothing is allowed until you allow it. Everything is set up in Settings → MCP server.

Turn it on

The Server and Access token sections: the MCP server switch on with "Listening on 127.0.0.1:8762", and the new token shown once
  1. Open Settings → MCP server.
  2. Under Access token, click Generate token. The token is shown once, under "Your new token — copy it now, it is not shown again". The connection snippets further down already contain it (see Connect your client).
  3. Switch on MCP server. Under the switch it says Listening on 127.0.0.1:8762 while the server runs, Stopped when it doesn't, or why it couldn't start.
  4. Turn on what clients may do (see What clients may do).

The switch always shows whether the server is really running, not just what you last chose. A server you left on starts again with Apiboo.

The server listens on your own computer only, http://127.0.0.1:8762/mcp. It can't be reached from another machine, and there is no setting to change that. Port changes the port (1024–65535) the next time the server starts; if the port is taken, the server doesn't start rather than moving to another one.

The access token

A client proves it may talk to Apiboo with the token, sent as Authorization: Bearer <token>.

  • Apiboo keeps only a hash of it, so it can never show it again. Copy it while it is on screen.
  • Regenerate makes a new one and immediately locks out every client that still has the old one. Paste the new one into each client.
  • Signing out clears your token and your permissions, and stops the server.

What clients may do

What clients may do with Allow all switched on, the read and write rows for every area, and the Destructive operations switch below it still off

Every area has a read and a write switch, and all of them start off. They are separate: write doesn't include read. A client doesn't even see the tools you haven't allowed.

AreaRead lets a clientWrite lets a client
DocumentsRead your document tree and a document's textCreate documents and folders, rename, move and change them
Agent notesRead the notes an agent left in the Agent Notes folderAdd notes for a later session
BoardsRead your boards, lists and tasks, and comments when it asksCreate boards and lists, add and change tasks, move cards, comment. New boards are personal; labels and people are not available.
CalendarRead your appointments for a date range, including repeating ones (not invitations you haven't accepted)Create and change appointments, with reminders
CollectionsList collections, folders and requests, read one request, list environments, diagnose a requestCreate, import, change and organise collections, folders and requests in the workspace you have open
TerminalSee the names of the servers you ticked, and collect the result of a command you approvedPropose commands and file writes on those servers. See Deploying with an agent.
GraphSee the names of your items and the links between them (see The Graph for AI agents)—

What a client never gets from Collections: a header value (apart from harmless ones like Content-Type), a body value, an auth credential, a variable's value (they come back as "hidden") or any part of a response. When it writes a request, it can't type a password or token into it; it has to use an Apiboo variable and ask you to fill it in.

Any read permission also lets a client list your scopes, which includes the names of your teams.

Allow all

Allow all turns every read and write switch on or off at once. It never turns on Allow destructive operations, and the terminal still needs a server ticked before it can reach one.

The destructive switch

Allow destructive operations is off by default. It unlocks eleven things:

  • emptying the Agent Notes folder;
  • deleting a document or folder;
  • deleting a task, a list or a whole board;
  • deleting an appointment;
  • deleting a request, a folder or a whole collection;
  • running a command on one of your servers;
  • writing a file to one of your servers.

Each of these needs the switch and its area's write permission. Deleting is permanent: it removes the item on your other devices and for your teammates too. A delete that would take more than the one thing the agent named, such as a folder with pages in it, is refused unless the agent confirms it on purpose, and the refusal lists what would go.

Approvals

Writes to documents, boards, the calendar and collections don't ask you each time: the permissions above are your answer. Commands and file writes on your servers are different. Every single one waits for you to press Approve in Apiboo, and the agent only ever sees the server's name. See Deploying with an agent.

Changes never overwrite yours

When an agent changes text that a person may have typed (a task, a board, a document's body, an appointment, a request), it has to send the revision it read, expected_rev. If you or a teammate changed it in the meantime, the write is refused with conflict, and the agent reads it again and retries. Your edit is never silently overwritten.

Rate limits

Per minute, while the server runs:

Kind of callLimit
All calls240
Reads240
Writes60
Destructive calls (including commands on servers)10
Collecting a command's result60

Over a limit, the client gets "Rate limited; retry in N s." and tries again later.

Recent requests

Recent requests shows how many calls the server has seen. Show requests opens the last 20: each tool name, allowed or denied, and why it was denied (for example a permission that is off, or a rate limit). It never records what a client sent or got back, and it lives in memory only. It's for finding out why something didn't work, not an audit log. Commands on your servers have their own log (see The command log).

Connect your client

The snippets under Connect your client already contain your address and token. Click the copy button next to one.

Claude Code

Run this once in a terminal:

claude mcp add --scope user --transport http apiboo http://127.0.0.1:8762/mcp --header "Authorization: Bearer <your token>"

Then start a new Claude Code session. --scope user makes it one entry for all your projects.

Connected before, with an older token? The old entry keeps answering 401 while Settings looks fine. Remove it first, then add it again:

claude mcp remove apiboo --scope user

If you once added it without --scope user, run claude mcp remove apiboo in each folder you added it in.

Cursor, Zed and other HTTP clients

Any client that connects to an MCP server over HTTP needs two things:

SettingValue
URLhttp://127.0.0.1:8762/mcp (or your port)
HeaderAuthorization: Bearer <your token>

Put them into the client's own MCP settings.

Agents in Apiboo's terminal

Claude Code and Codex started from an Apiboo terminal pane connect by themselves. With Attach Apiboo MCP on in the terminal profile (it is by default for both), the pane gets its own temporary token with exactly your current permissions. It lives in memory and ends with the pane. The pane shows an MCP chip while it is attached, or MCP off when the server is off. Inside the agent the server is called apiboo_app, so it doesn't clash with an apiboo entry of your own.

Cursor CLI reads MCP servers only from its own mcp.json, which Apiboo doesn't edit, so attach isn't available for it. See Agents in the terminal.

Claude Desktop

Claude Desktop (and Claude on the web and mobile) reaches MCP servers from Anthropic's cloud, so it can't open 127.0.0.1 directly. It connects through a small helper program that runs on your computer.

  1. In MCP server for Claude Desktop, click Install MCP Server. Apiboo downloads the helper, signed, from the same place its updates come from, and checks it. It then shows Installed — version … and Installed at with the path.
  2. Under Connect your client → Claude Desktop, copy the configuration. It looks like this, with the path and token filled in:

    {
      "mcpServers": {
        "apiboo": {
          "command": "<path to apiboo-mcp-bridge>",
          "args": [
            "--url",
            "http://127.0.0.1:8762/mcp"
          ],
          "env": {
            "APIBOO_MCP_TOKEN": "<your token>"
          }
        }
      }
    }
  3. Add it to Claude Desktop's claude_desktop_config.json yourself. Apiboo doesn't edit that file.
  4. Restart Claude Desktop.

Apiboo has to be running with the MCP server on; otherwise the helper answers "Apiboo is not running". After an Apiboo update the section offers Update MCP Server; the installed helper keeps working until you do.

What MCP can never see

The Vault and everything in it, saved passwords and API keys, the values of environment and workspace variables, request authentication, database, FTP and SSH credentials, your account tokens and captured mail. There are no tools for any of it.

The one deliberate exception is yours to make: an SSH connection you tick under Terminal — which servers can be used by name to run a command you approve. Even then its password and key stay inside Apiboo.

Troubleshooting

"Connected · 0 tools"

The client reached Apiboo but got no tools. Check, in this order:

  1. Permissions. With nothing allowed under What clients may do, the tool list is empty on purpose. Turn on at least one read switch.
  2. Start a new session. A client builds its tool list once, when the session starts. After you change a permission, update Apiboo or fix the connection, start a new Claude Code session (or restart the client).
  3. The server runs. Settings → MCP server must say Listening on 127.0.0.1:…. Signing out stops it, and it stays off until you switch it on.
  4. The token is current. If you regenerated it, the client still has the old one and gets 401. Remove the entry and add it again (see Claude Code).

Other problems

SymptomCause and fix
A tool the agent expects is "Unknown tool"Its permission, or the destructive switch, is off. Unknown and not-allowed look the same to the client on purpose.
The server doesn't start, "port … is unavailable"Another program uses the port. Pick another Port and switch the server off and on.
"Generate an access token before starting the MCP server."Generate a token first.
Writes fail with conflictSomeone changed the item since the agent read it. The agent should read it again and retry.
Calls fail with "Rate limited"See Rate limits.