MCP server

Let your AI agent read the product signals of one Cleansig workspace. Read-only, signed in with OAuth, revocable at any time.

Server URL : https://api.cleansig.com/api/v1/mcp

Overview

Cleansig runs a remote MCP server. Once connected, your agent can search signals, read their quotes and follow your loop, in the workspace you chose when you authorized it.

  • Transport : Streamable HTTP
  • Authentication : OAuth 2.1 with PKCE, or an access key
  • Access : Read-only
  • Scope : One workspace per connection

Quickstart

  1. Add the server. In your client, add a remote MCP server with the server URL above.
  2. Authorize. A Cleansig page opens. Sign in, pick the workspace, then select Allow access.
  3. Ask. Your agent can now answer questions about your signals.
  • What's waiting to be qualified in Cleansig?
  • Which signals are ready to decide, and why?
  • Show me what users said about large file imports.

Connect a client

Claude (web and desktop)

  1. Open Settings, then Connectors, then Add custom connector.
  2. Name it Cleansig and paste the server URL.
  3. Authentication: Sign in now. OAuth client: Use Claude's published identity.
  4. Select Add, then Allow access on the Cleansig page.

ChatGPT

  1. Open Settings, then Apps & Connectors, then Advanced settings, and turn on Developer mode.
  2. Select Create. Name it Cleansig and paste the server URL.
  3. Authentication: OAuth.
  4. Allow access on the Cleansig page.

Developer mode is available on the web app, on Plus, Pro, Business, Enterprise and Education plans.

Claude Code

  1. Add the server:
    claude mcp add --transport http cleansig https://api.cleansig.com/api/v1/mcp
  2. Start Claude Code, run /mcp, select cleansig, then Authenticate.

Cursor

  1. Add the server to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project):
    {
      "mcpServers": {
        "cleansig": {
          "url": "https://api.cleansig.com/api/v1/mcp"
        }
      }
    }
  2. Open Cursor Settings, then MCP, and select Connect next to cleansig.

Codex

  1. Add the server:
    codex mcp add cleansig --url https://api.cleansig.com/api/v1/mcp
  2. Sign in:
    codex mcp login cleansig

VS Code

  1. Add the server to .vscode/mcp.json:
    {
      "servers": {
        "cleansig": {
          "type": "http",
          "url": "https://api.cleansig.com/api/v1/mcp"
        }
      }
    }
  2. Select Start above the server, then sign in when VS Code asks.

Other clients

Any MCP client that supports Streamable HTTP and OAuth works. It discovers everything from the server URL: a request without a token gets a 401 whose WWW-Authenticate header points to the metadata below.

Tools

Every tool is read-only and scoped to the connected workspace.

  • search_signals (query) : Signals whose problem matches a phrase, by meaning rather than keywords.
  • read_signal (signal_id) : One signal: statement, theme, maturity, sources, trend, requested solutions, Jira key.
  • read_verbatims (signal_id) : The quotes behind a signal, with their source.
  • find_similar_signals (signal_id) : Signals close to a given one, with a similarity score.
  • read_loop_state (none) : How many signals sit at each stage of the loop.
  • list_signals_at_stage (stage, limit (≤ 50), offset) : Signals at one stage, most urgent first, with total and has_more.

Authentication

Clients authorize with OAuth 2.1. You never copy a secret.

  • Clients register automatically (Dynamic Client Registration) or with a Client ID Metadata Document.
  • PKCE with S256 is required. Authorization codes are single-use and expire after 5 minutes.
  • Access tokens last 1 hour. Refresh tokens last 60 days and rotate on every use.
  • The only scope is mcp:read.

Access keys

For scripts, your own agent, or clients without OAuth. Create a key in Settings › Agents. It is shown once and reads the workspace it was created in.

X-API-Key: csk_…
Authorization: Bearer csk_…

Limits and errors

  • 401: no credentials, or an invalid, expired or revoked one. The WWW-Authenticate header says where to authorize.
  • A tool that refuses an argument answers with isError: true, not a protocol error, so the agent can correct its call.
  • list_signals_at_stage returns at most 50 signals per call. Use offset to read the next page.
  • Access ends as soon as the person is removed from the workspace or their account is suspended.

Security and data

  • Read-only: an agent cannot qualify, change or delete anything.
  • One workspace per connection. Your other workspaces stay out of reach.
  • Disconnect an app or revoke a key in Settings › Agents. It takes effect immediately.
  • Tokens and keys are stored as SHA-256 hashes, never in clear.
  • What your agent reads is processed by its provider (Anthropic, OpenAI…) under that provider's terms.