Docs · Developers

MCP server

SourceFinch runs a remote Model Context Protocol server, so AI assistants such as Claude, ChatGPT, Cursor or VS Code can find and configure your sources, run them, and read records together with the evidence each value came from and its usage rights. It uses the same API, limits and permissions as the REST API and the SDK.

Connect

Add a remote (Streamable HTTP) MCP server with this URL:

https://sourcefinch.com/mcp

Your client opens a SourceFinch sign-in and consent page. Choose the project it may use and whether it may also make changes (editors and owners only). The client receives a token for that project only, refreshed every hour. Disconnect it any time in Console → Security → Connected apps.

Claude Code, for example:

claude mcp add --transport http sourcefinch https://sourcefinch.com/mcp

Headless agents can skip OAuth and send a project API key instead: Authorization: Bearer sec_….

Tools

ToolGroupWhat it does
whoamireadThe project and scopes this connection has.
find_sourcesreadSearch your sources by name or URL.
describe_sourcereadRecipe, schedule, versions, latest usage rights and acquisition path.
get_recordsreadCurrent records, each with its evidence id and field locators, plus usage rights and the signed manifest hash.
get_changesreadField-level changes between runs (before and after).
list_runs / get_runreadRuns, their status, failure class and compliance state at capture.
get_evidencereadCaptures by id or run; optionally the capture text, checked against its SHA-256.
get_run_manifestreadThe signed manifest and its RFC 3161 timestamp anchor.
export_runreadA run's records as CSV, JSON or NDJSON with evidence references.
export_evidence_bundlereadThe WACZ evidence bundle, for offline verification.
create_sourcebuildStart monitoring a source (with dry_run to validate first).
update_sourcebuildChange schedule, record key, URL or recipe (dry_run shows the diff).
run_sourcebuildRun a source now, optionally waiting up to 60 s.
accept_runbuildAccept a degraded run as correct.
list_destinations / configure_deliverydeliverSigned webhook destinations: create, pause, test.
list_deliveries / redeliverdeliverDelivery receipts and redelivery.

Read tools are marked read-only; write tools are hidden from read-only connections. To load only some tools, connect to https://sourcefinch.com/mcp?groups=read (groups: read, build, deliver). Sources and runs are also resources: sourcefinch://sources/{id}, sourcefinch://sources/{id}/records, sourcefinch://runs/{id}.

Ground rules

For client developers

Authorization follows the MCP specification: protected resource metadata at /.well-known/oauth-protected-resource/mcp, authorization server metadata at /.well-known/oauth-authorization-server, dynamic client registration, authorization code with PKCE (S256), the resource parameter, and rotating refresh tokens. Clients are public (no secret). Supported protocol versions: 2025-11-25, 2025-06-18 and 2025-03-26.