Set up MCP, access keys, WebDAV and webhooks

Connect external tools and define their access. MCP, WebDAV and module-specific webhooks serve different purposes.

Prerequisites
  • You are signed in with access to the required modules.
  • You know the intended client and target organization.

Connect an MCP client

The app's /mcp/setup page provides your instance's server URL ending in /api/mcp. Compatible clients can use its sign-in/consent flow. All available tools, permissions and workflows are described in the "MCP interface" section.

  1. Open Account → Integrations and the MCP setup guide.
  2. Copy its server URL to your client.
  3. Sign in, review the consent page and approve the intended connection.
  4. Verify the organization using a read request.

Create a key with appropriate access

MCP and WebDAV keys are separate. Full tokens appear only once after creation.

Name
Required label identifying the client or device.
Read only
List and read data.
Read + Write
Also create and update.
Full access
Read, write and delete; initially selected, so check the required scope.
Account-wide
Works across your memberships with an explicit organization per request. Otherwise the key is bound to the active organization.
  1. Open the correct key section and start creation.
  2. Set name, access level and account-wide choice.
  3. Create and copy the token directly to the intended client.
  4. For account-wide MCP, add X-Organization-Slug as shown by the setup guide.

Set up WebDAV

Use the WebDAV key section and /webdav/setup for a network-drive/file client.

  1. Create a WebDAV key with the required scope.
  2. Copy the setup guide's address and authentication format into your client.
  3. Verify folder access and, if intended, writing.

Revoke keys and locate webhooks

Key lists show metadata and last use. CRM webhooks live in CRM settings; chat webhooks live in channel settings.

  1. Identify the obsolete key by name and last use and revoke it.
  2. Create a replacement only if the client still needs access.
  3. Configure CRM or chat webhooks in the corresponding module, following its displayed request format.

Common pitfalls

  • Tokens cannot be revealed again

    Replace a lost token and revoke the unused key.

  • Purpose and context matter

    WebDAV and MCP keys are distinct. Account-wide access requires an organization context and does not grant new memberships.

Keep reading

Still have a question or a problem?

Visit support

Last reviewed on 2026-09-13