Skip to guide

Use Escanor

Escanor MCP

Give your coding agents five MCP tools that reach your connected integrations, with a revocable key and no credentials pasted into prompts.

Last updated

On this page

MCP (the Model Context Protocol) is how coding agents such as Claude Code discover and call tools. Escanor runs one MCP server that sits in front of supported connected integrations, so your agent needs one connection instead of dozens.

Five tools, thousands of operations

An agent does not get a tool per operation (the cloud providers alone have thousands). It gets five:

ToolDoes
escanor_list_providersWhich providers exist.
escanor_connection_statusWhich of them your workspace has connected, and which need reconnecting.
escanor_list_toolsThe operations for one provider (searchable and paged).
escanor_usage_statsUsage and rate limits.
escanor_invokeRuns one operation by its id.

The agent finds an operation with escanor_list_tools and runs it with escanor_invoke. If a provider is not connected, the response says so.

Whose credentials a call uses

Each call runs with your workspace's stored credential for that provider, bound only for the length of the call. Calls to the same provider run one at a time, to reduce credential context overlap. Provider operations use server-side credentials; do not place those credentials in tool arguments or agent prompts.

Connect an agent

Open MCP in the dashboard. It creates a key for you and shows the exact steps and text to copy for your app, already filled in with your address and key:

AppHow it connects
Claude CodePaste the one-line command it shows into your terminal.
Claude DesktopAdd the snippet to claude_desktop_config.json (it uses the mcp-remote helper) and restart.
CursorPaste the configuration into ~/.cursor/mcp.json or the MCP settings.
VS CodePaste the configuration into .vscode/mcp.json, then use Copilot Chat in agent mode.
ChatGPTAdd a custom connector with the server address and sign in with your Escanor account. There is no key to copy.
Anything elseAny app that supports remote MCP servers can use the server address and an Authorization: Bearer <key> header.

The key is shown once. Then ask your agent: "List the tools you can use from Escanor." It should answer with the five tools above.

Keys and activity

  • Every key is listed with its last use. Revoke a key to cut off the agent immediately.
  • MCP activity shows each call in plain language, so you can see what an agent did and ask the assistant about any call.
  • Keys are tied to your workspace and have the permissions of your plan.

Good practice

  • One key per agent or per machine, named after it, so you can revoke one without touching the others.
  • Connect integrations with the narrowest permissions that do the job.
  • Keep approvals on for anything destructive.

Discovery and invocation schemas

Use the MCP client's tool-call interface after it initializes the remote connection. The following are tool arguments, not unauthenticated REST requests:

{"provider":"github","query":"repository","limit":20,"offset":0}

Pass that object to escanor_list_tools. provider is required; query is optional, limit defaults to 100 and is clamped to 1–500, and offset defaults to zero. Read the returned operation's input_schema before calling it. The first page may be incomplete; advance offset to browse additional results.

escanor_invoke accepts a required tool_id and an optional object arguments. Use the exact discovered ID and its schema:

{"tool_id":"<discovered-provider.operation>","arguments":{}}

This placeholder is not an executable operation. Fill only the fields required by the discovered schema. Do not invent an operation name based on an example. escanor_usage_stats accepts days (default 7). Provider and connection discovery take no arguments.

Scopes and failures

Discovery requires mcp:read; invocation requires mcp:invoke. A scoped read-only token can additionally reject a write with read_only_token, or exhaust a limited allowed-write budget. After an insufficient_scope response, review the token's grants; do not add credentials to arguments.

After provider_not_found, discover the available provider names first. After unauthorized, check or replace the MCP token. For rate_limit_exceeded, wait and inspect usage. Reconnect a refused provider grant in Integrations. A working MCP transport can still return an operation error. Read the operation result and verify the provider state before retrying a write.

Related: Keys, OIDC, Permissions and approvals.

Need help? Contact support with a redacted error and the affected version.