CloudCrane MCP
Connect your AI agent to CloudCrane over MCP.
CloudCrane turns a messy catalog into data an agent can be trusted with. Rulesrun before any model, the model may only answer from values you allowed, andevery value carries a receipt saying how it was decided. Safety exclusions areenforced in the database query, so a record whose value is unknown is left outrather than assumed safe.
There are two MCP endpoints. Both speak Streamable HTTP (stateless, no SSE stream).
| Endpoint | Signs in with | What it opens |
|---|---|---|
https://cloudcrane.ai/api/build/mcp |
Your CloudCrane account (OAuth), or a build key cc_build_โฆ |
Your workspace, for your own agent while you build |
https://cloudcrane.ai/api/mcp/<tool> |
A tool key cc_live_โฆ |
One deployed tool, for your end users' agents |
The workspace MCP
Let your own agent read what you are building and, if you allow it, help build it.
Connect with OAuth
In an MCP client that supports OAuth sign-in, add the URL with no key:
https://cloudcrane.ai/api/build/mcp
The client opens a CloudCrane page where a workspace owner picks the workspaceand what the agent may do, then signs you in. Or install it fromSmithery.
Tested with Cursor, Cline and Smithery. Exact settings for each arein llms-install.md, which an agent can follow to set it up.
Cursor (~/.cursor/mcp.json):
{ "mcpServers": { "cloudcrane": { "url": "https://cloudcrane.ai/api/build/mcp" } } }
Cline (cline_mcp_settings.json):
{ "mcpServers": { "cloudcrane": { "transport": { "type": "streamableHttp", "url": "https://cloudcrane.ai/api/build/mcp" } } } }
The page shows where it will send you back before anything else, because anapp's name is only what it calls itself. It starts on read only. Each app youapprove shows up in the dashboard under Developers, where you can revoke it.
Or with a build key
For a client without OAuth, an owner makes a build key under Developers andsends it as a header:
claude mcp add --transport http cloudcrane https://cloudcrane.ai/api/build/mcp \
--header "Authorization: Bearer $CLOUDCRANE_BUILD_KEY"
What it can do
Every connection reads: list_datasets, get_dataset, list_contracts,get_readiness, list_review_items, get_receipts, list_value_sets, get_run.They run inside a read-only database transaction.
A connection allowed to build also gets: create_dataset, create_field,update_field, create_value_set, import_value_set_version, start_run,publish_release. Each goes through the same checks as the dashboard and isrecorded as made by that connection.
What no connection can do: publish past the accuracy gate, decide a reviewitem, edit a stored value, withhold a record, delete anything, or remove a valuefrom a safety field. Those stay with a person, because a receipt names who decided.
Imported record contents stay hidden unless the owner turns them on. Theworkspace MCP is included in every CloudCrane plan, Free too.
Full reference: cloudcrane.ai/docs/build-mcp.
A deployed tool
Each tool you deploy is its own MCP server. Your agent sees search_<tool> andget_<tool>, plus find_values when the tool has value set fields. Their inputschema is generated from your contracts, so the agent picks values from an enumof your list and cannot ask for one you never defined.
Claude Code
claude mcp add --transport http catalog https://cloudcrane.ai/api/mcp/catalog \
--header "Authorization: Bearer $CLOUDCRANE_TOOL_KEY"
Claude Desktop, Cursor, Windsurf
{
"mcpServers": {
"catalog": {
"url": "https://cloudcrane.ai/api/mcp/catalog",
"headers": { "Authorization": "Bearer cc_live_..." }
}
}
}
Some clients call the block servers instead of mcpServers, and some want "type": "http" next to the url.
- n8n: MCP Client Tool node, transport HTTP Streamable, Bearer authentication.
- LangChain:
MultiServerMCPClientwith transportstreamable_httpand a headers dict. - OpenAI Agents SDK:
MCPServerStreamableHttpwith the url and headers.
The same tool also answers plain REST at POST /api/v1/tools/<tool>/search.Full reference: cloudcrane.ai/docs/deploy.
Things that look like a broken server
- 406: MCP requires
Accept: application/json, text/event-streamon every POST, even though these endpoints never send a stream. - 405 on GET: the endpoints are stateless and offer no SSE stream, so only POST is allowed. A client that silently falls back to SSE connects but lists no tools.
- 403 on the workspace MCP: it opens a whole workspace, so a request from a browser (any request with an
Originheader) is refused. Call it from a server or a desktop client.
Links
- Docs
- Playground: the pipeline in your browser, no sign-up
- Integrations
This repository holds documentation and the registry entry (server.json), notthe server's source.