Use Escanor
Escanor MCP
Give your coding agents five MCP tools that reach your connected integrations, with a revocable key and no credentials pasted into prompts.
Last updated
On this page
MCP (the Model Context Protocol) is how coding agents such as Claude Code discover and call tools. Escanor runs one MCP server that sits in front of supported connected integrations, so your agent needs one connection instead of dozens.
Five tools, thousands of operations
An agent does not get a tool per operation (the cloud providers alone have thousands). It gets five:
| Tool | Does |
|---|---|
escanor_list_providers | Which providers exist. |
escanor_connection_status | Which of them your workspace has connected, and which need reconnecting. |
escanor_list_tools | The operations for one provider (searchable and paged). |
escanor_usage_stats | Usage and rate limits. |
escanor_invoke | Runs one operation by its id. |
The agent finds an operation with escanor_list_tools and runs it with escanor_invoke. If a provider is not connected, the response says so.
Whose credentials a call uses
Each call runs with your workspace's stored credential for that provider, bound only for the length of the call. Calls to the same provider run one at a time, to reduce credential context overlap. Provider operations use server-side credentials; do not place those credentials in tool arguments or agent prompts.
Connect an agent
Open MCP in the dashboard. It creates a key for you and shows the exact steps and text to copy for your app, already filled in with your address and key:
| App | How it connects |
|---|---|
| Claude Code | Paste the one-line command it shows into your terminal. |
| Claude Desktop | Add the snippet to claude_desktop_config.json (it uses the mcp-remote helper) and restart. |
| Cursor | Paste the configuration into ~/.cursor/mcp.json or the MCP settings. |
| VS Code | Paste the configuration into .vscode/mcp.json, then use Copilot Chat in agent mode. |
| ChatGPT | Add a custom connector with the server address and sign in with your Escanor account. There is no key to copy. |
| Anything else | Any app that supports remote MCP servers can use the server address and an Authorization: Bearer <key> header. |
The key is shown once. Then ask your agent: "List the tools you can use from Escanor." It should answer with the five tools above.
Keys and activity
- Every key is listed with its last use. Revoke a key to cut off the agent immediately.
- MCP activity shows each call in plain language, so you can see what an agent did and ask the assistant about any call.
- Keys are tied to your workspace and have the permissions of your plan.
Good practice
- One key per agent or per machine, named after it, so you can revoke one without touching the others.
- Connect integrations with the narrowest permissions that do the job.
- Keep approvals on for anything destructive.
Discovery and invocation schemas
Use the MCP client's tool-call interface after it initializes the remote connection. The following are tool arguments, not unauthenticated REST requests:
{"provider":"github","query":"repository","limit":20,"offset":0}Pass that object to escanor_list_tools. provider is required; query is optional, limit defaults to 100 and is clamped to 1–500, and offset defaults to zero. Read the returned operation's input_schema before calling it. The first page may be incomplete; advance offset to browse additional results.
escanor_invoke accepts a required tool_id and an optional object arguments. Use the exact discovered ID and its schema:
{"tool_id":"<discovered-provider.operation>","arguments":{}}This placeholder is not an executable operation. Fill only the fields required by the discovered schema. Do not invent an operation name based on an example. escanor_usage_stats accepts days (default 7). Provider and connection discovery take no arguments.
Scopes and failures
Discovery requires mcp:read; invocation requires mcp:invoke. A scoped read-only token can additionally reject a write with read_only_token, or exhaust a limited allowed-write budget. After an insufficient_scope response, review the token's grants; do not add credentials to arguments.
After provider_not_found, discover the available provider names first. After unauthorized, check or replace the MCP token. For rate_limit_exceeded, wait and inspect usage. Reconnect a refused provider grant in Integrations. A working MCP transport can still return an operation error. Read the operation result and verify the provider state before retrying a write.
Related: Keys, OIDC, Permissions and approvals.
Need help? Contact support with a redacted error and the affected version.