Menu
Managing MCP servers
Create an MCP server from your workflow routes, connect Claude Desktop, Cursor or Claude Code, manage API keys, require sign-in and attach it to an assistant.
On this page
What an MCP server is
An MCP server lets AI assistants and tools such as Claude Desktop, Cursor and Claude Code use your workflows. You choose which workflow routes to expose, and each becomes a tool the AI can call. The AI reads each tool's name and description to decide when to use it, then calls the route and gets the response back.
MCP servers are also how your own assistants reach your workflows: an assistant can only do what the servers attached to it expose.
Creating a server
- Open MCP Servers and select New MCP Server.
- Enter a Server name, for example "Commerce Tools".
- Write a Description of what an AI can do with this server. Generate with AI drafts one from the routes you picked, so select your routes first.
- Under Select routes, tick the routes to expose. Workflows are listed with their routes, each showing its method, whether it is Public or Private, and its path. Tick a workflow to select all its routes, and use the search box to find one. At least one route is required, and only routes can become tools.
- Choose the optional settings below, then select Generate MCP Server.
- Include workflow name in tool name: when off, tools are named by route slug only, like
get_products. When on, the workflow slug is added in front, likecommerce_get_products. Turn it on if routes in different workflows share names. - Environment (optional): run every tool call from this server in one environment. Leave it unset to use whatever environment the called workflow runs in by default.
- Gateway workflow: send every tool call through one workflow instead of each tool's own. Choose the workflow when you tick it.
The server gets a slug automatically, and it is shown on the server's page. The list shows each server's status (Active or Inactive) and how many tools it has, and you can search by name or slug.
To change the name, description, routes or settings later, open the server and select Edit.
The server page
Select a server to manage it. The header shows its status and slug, with Activate or Deactivate, Edit and Delete. Deactivating stops it serving without deleting anything. There are four tabs: Overview, API Keys, Widgets and Authentication.
Overview
- Connect to your AI client has ready-made snippets, covered below.
- Tools lists everything the server exposes, with each tool's name, method, description and route path. Tools come from the routes you selected; to change them, edit the server.
Tool descriptions matter as much as the tools. The AI picks tools by reading them, so describe each route clearly.
Connecting an AI client
Choose the tab for your client on the Overview tab, copy the snippet and replace <your-api-key> with a key from the API Keys tab.
| Client | Where it goes |
|---|---|
| Claude Desktop | Your claude_desktop_config.json, then restart Claude Desktop. Needs Node.js. |
| Cursor | Cursor's MCP settings (Settings → MCP). Needs Node.js. |
| Claude Code | Your project's .mcp.json file or Claude Code's global settings. |
If you turn on OAuth for the server (see below), the snippets leave out the API key, because the client signs in instead.
API keys
A key is how a client proves it may use the server. Keep one per client so you can cut one off without affecting the others.
- Open API Keys and select Add Key.
- Enter a label, such as "Claude Desktop" or "Production", and select Generate.
- Copy the key before closing. It is shown once and can't be shown again; the confirmation button reads I've saved it.
Each key shows its label, the start of the key, how many calls it has made and when it was last used. A revoked key is marked Revoked.
- Rotate key gives a client a new key. The old one stops working immediately, so reconfigure any client using it.
- Delete key removes it, and clients using it are disconnected immediately.
Requiring sign-in
By default a client needs only an API key. Turn on OAuth Authentication under Authentication to make clients sign in too. Choose a Login Method:
- Custom Login sends the username and password to a workflow you wrote. Choose the Login Workflow and Route Path, and name the Username Field and Password Field it expects.
- OAuth Provider redirects to an external identity provider. Give it the Authorization URL, Token URL, Client ID, Client Secret and Scopes.
Set a Login Page Title if you like. Forwarded headers pass values from the sign-in response on to your workflows with every tool call, so the workflows know who is signed in. Session Expiry sets how long before the client must sign in again: 1 hour, 8 hours, 1 day (the default), 7 days, 30 days, or a custom number of seconds. Select Save authentication settings to apply it.
The same login and forwarded-header rules apply as for assistants; see Authentication in the assistant guide for how the sign-in verdict and header templates work.
Widgets
The Widgets tab controls how each tool's response looks in an assistant's chat. A tool with no widget answers as plain text. See Widgets in chat for choosing and mapping a widget. For each tool the tab also lets you:
- Add Questions shown to the shopper alongside the answer.
- Set up Ask for missing fields, a short form shown when the AI hasn't supplied required inputs.
- Remember values from a response and send them in later calls.
- Run a read-only workflow first with Run before.
Exposing a search index or data
Only workflow routes become tools. To let an assistant search an index or read data, build a workflow route that does it, for example with the Search connector or the Data Table connector, and expose that route on a server.
Moving servers between stores
Export and Import at the top of the list copy servers as JSON. Secrets are never included, so an imported server needs its client secret set again. An import never overwrites: if a slug already exists, the import stops and tells you which, so you can rename it first.
Deleting a server
Select the trash icon on a server, or Delete on its page. All of its API keys are deleted permanently, and AI clients connected through it lose access immediately. Assistants that had it attached lose its tools.
Last updated 9 October 2026