MCP CONNECTIONSAPI docs

YOUR TOOLS. YOUR PERMISSIONS.

Bring your workspace
to your AI assistant.

Read projects and update permitted tasks with a connection you control.

MCP Streamable HTTP endpointhttps://mcp.aloca.io/mcp

Opening this page does not connect an account. Connection requires a registered OAuth client and your approval on ALOCA.

ChatGPT verification is pending

ChatGPT is the first selected client. Its exact callback and authentication method must be taken from the actual connection setup. A successful end-to-end connection has not yet been confirmed.

Before you connect

  1. The platform owner opens Admin → OAuth clients and registers the application's exact HTTPS callback, authentication method and scopes.
  2. Configure that client ID in the AI application's MCP connection. Use the endpoint above. If required, provide the client secret securely.
  3. Sign in on aloca.io. Review the client name, workspace, permissions and selected records.
  4. Approve the connection. Disconnect it later in Settings → API & MCP.

Authorization uses PKCE S256, short-lived access tokens and rotating refresh tokens. It does not share your password or browser session with the AI application.

The authorization issuer is https://aloca.io. Discovery is available at the protected-resource metadata endpoint. Dynamic client registration is not supported.

What the connection can do

Viewer, Editor and Task worker roles remain enforced. A selected task does not reveal unrelated project data. The connection cannot send email, delete records or use administrator controls.

Updates require the current revision and a UUID idempotency key. REST tokens and MCP tokens have separate audiences.

Read the operation and permission contract