Docs · Developers
MCP server
SourceFinch runs a remote Model Context Protocol server, so AI assistants such as Claude, ChatGPT, Cursor or VS Code can find and configure your sources, run them, and read records together with the evidence each value came from and its usage rights. It uses the same API, limits and permissions as the REST API and the SDK.
Connect
Add a remote (Streamable HTTP) MCP server with this URL:
https://sourcefinch.com/mcp
Your client opens a SourceFinch sign-in and consent page. Choose the project it may use and whether it may also make changes (editors and owners only). The client receives a token for that project only, refreshed every hour. Disconnect it any time in Console → Security → Connected apps.
Claude Code, for example:
claude mcp add --transport http sourcefinch https://sourcefinch.com/mcp
Headless agents can skip OAuth and send a project API key instead: Authorization: Bearer sec_….
Tools
| Tool | Group | What it does |
|---|---|---|
whoami | read | The project and scopes this connection has. |
find_sources | read | Search your sources by name or URL. |
describe_source | read | Recipe, schedule, versions, latest usage rights and acquisition path. |
get_records | read | Current records, each with its evidence id and field locators, plus usage rights and the signed manifest hash. |
get_changes | read | Field-level changes between runs (before and after). |
list_runs / get_run | read | Runs, their status, failure class and compliance state at capture. |
get_evidence | read | Captures by id or run; optionally the capture text, checked against its SHA-256. |
get_run_manifest | read | The signed manifest and its RFC 3161 timestamp anchor. |
export_run | read | A run's records as CSV, JSON or NDJSON with evidence references. |
export_evidence_bundle | read | The WACZ evidence bundle, for offline verification. |
create_source | build | Start monitoring a source (with dry_run to validate first). |
update_source | build | Change schedule, record key, URL or recipe (dry_run shows the diff). |
run_source | build | Run a source now, optionally waiting up to 60 s. |
accept_run | build | Accept a degraded run as correct. |
list_destinations / configure_delivery | deliver | Signed webhook destinations: create, pause, test. |
list_deliveries / redeliver | deliver | Delivery receipts and redelivery. |
Read tools are marked read-only; write tools are hidden from read-only connections. To load only some tools, connect to https://sourcefinch.com/mcp?groups=read (groups: read, build, deliver). Sources and runs are also resources: sourcefinch://sources/{id}, sourcefinch://sources/{id}/records, sourcefinch://runs/{id}.
Ground rules
- Runs started by an assistant count against your plan like any other run; failed runs are free.
- SourceFinch respects robots.txt and never bypasses logins or bot challenges, whoever asks. Create sources only for data you have the right to collect.
- Usage rights describe documented provenance and terms at capture time. They are not legal advice.
For client developers
Authorization follows the MCP specification: protected resource metadata at /.well-known/oauth-protected-resource/mcp, authorization server metadata at /.well-known/oauth-authorization-server, dynamic client registration, authorization code with PKCE (S256), the resource parameter, and rotating refresh tokens. Clients are public (no secret). Supported protocol versions: 2025-11-25, 2025-06-18 and 2025-03-26.