Engramic MCP server

Documentation for administrators and developers.

Last updated: 1 October 2026

1. Overview

Engramic is the knowledge graph a team authors: its decisions, goals, constraints and gaps. The Engramic MCP server lets AI agents read that graph and record to it, so an agent working in Claude, Cursor or another MCP client starts from what your team has already decided.

This page is for the people who set up and approve the connector: workspace owners, IT administrators and security reviewers. It describes how the connector signs in, what it can do, where data goes and what administrators can control.

Requirements

  • An Engramic account and a workspace.
  • The connector works on every Engramic plan, including Free.

2. Connect

The server is remote and uses streamable HTTP. There is nothing to install or host.

https://api.engramic.ai/mcp

Claude web and desktop

Go to Settings, then Connectors, then Add custom connector, and enter the server URL above. On Claude Team and Enterprise plans, an owner or admin adds it under Organization settings, then Connectors.

Claude Code

claude mcp add --transport http --scope user engramic https://api.engramic.ai/mcp
/mcp

Run /mcp inside Claude Code to sign in. We also recommend the Engramic plugin, which records key decisions from Claude Code sessions. Steps are on the Engramic for Claude page.

Other clients

Setup steps for Cursor, VS Code, Codex and Windsurf are at app.engramic.ai/connect.

3. Authentication

The server uses OAuth 2.1 with PKCE (S256 only) and dynamic client registration. There are no API keys or tokens to paste.

At sign-in, the user picks the workspace and who the connection acts as: themselves, or a named agent they manage. Each connection is bound to one workspace. The consent screen shows the domain the app will return you to, and flags apps Engramic doesn't recognise.

StandardOAuth 2.1, PKCE with S256 only, dynamic client registration
Protected resource metadata (RFC 9728)https://api.engramic.ai/.well-known/oauth-protected-resource
Authorisation server metadata (RFC 8414)https://api.engramic.ai/.well-known/oauth-authorization-server
Authorisation codesLast 10 minutes and are single use
Access tokensLast 1 hour
Refresh tokensLast 30 days, rotate on every use and are stored hashed
RevocationSupported (RFC 7009)
Workspace bindingEach connection is bound to one workspace

4. Permissions

A connection acts with the signed-in user's own workspace role, checked on every request. Owners and contributors can use read and write tools. Viewers can use every read-only tool except Open Share.

Every write appears on the workspace timeline, credited to the person or named agent that made it.

No tool deletes anything. The Update tools are flagged destructive because an update replaces a field's previous value.

5. Tools reference

Read-only tools do not change workspace content. Write tools create or change content and need an owner or contributor role.

ToolTitleWhat it doesType
engramic_search
Search EngramicFind topics and timeline events by text.Read-only
ask_alia
Ask AliaAsk one question and get one answer synthesised from the workspace by Engramic’s assistant, Alia.Read-only
engramic_summary
Workspace SummaryThe caller’s identity and a workspace overview.Read-only
engramic_topic
Browse TopicBrowse the topic graph one level at a time.Read-only
engramic_timeline
Query TimelineDecisions, actions, events and discoveries, filtered by type, actor, topic or date.Read-only
engramic_event
Get EventOne timeline event in full.Read-only
engramic_open_share
Open ShareOpen a shared topic snapshot by its ID. Each open is logged (not available to viewers).Read-only
engramic_record_draft
Draft RecordStage a decision, action, event or discovery and get the topic’s context first.Write
engramic_record_publish
Publish RecordPublish a staged record to the timeline.Write
engramic_create_concept
engramic_create_goal
engramic_create_gap
engramic_create_constraint
engramic_create_resource
Create Concept, Create Goal, Create Gap, Create Constraint, Create ResourceCreate a topic of that type.Write
engramic_update_concept
engramic_update_goal
engramic_update_gap
engramic_update_constraint
engramic_update_resource
Update Concept, Update Goal, Update Gap, Update Constraint, Update ResourceChange a topic’s fields.Write, destructive

6. Data handling

What passes through the connector

The workspace's topics, timeline and shares, as read and written by the tools above.

Hosting, encryption at rest and backups

Each workspace has its own separate database. Engramic's servers run on AWS in London, UK (eu-west-2). Cloudflare delivers the website and app.

HostingAWS, London, UK (eu-west-2)
Encryption at restData is stored on encrypted volumes (AWS EBS encryption)
BackupsAutomated hourly backups using AWS Backup

Third parties

Only Ask Alia sends data outside Engramic. It sends the relevant workspace content and the question to Anthropic's API to generate the answer. No other tool calls an AI model.

Engramic uses Anthropic's API under Anthropic's standard commercial terms, under which Anthropic does not use API inputs or outputs to train its models.

Your content is not used to train third-party AI models. It is processed only to produce the response you asked for.

Retention

Deleting a workspace archives it, and it is permanently deleted after 30 days. For account data and deletion requests, see the privacy policy or email [email protected].

7. Admin controls

  • Owners invite members, set roles, and deactivate or remove members.
  • Deactivating or removing a member ends their connector access on their next request.
  • Users see and revoke their connections under Account, then Connected apps. Revoking deletes that connection's refresh tokens at once. An access token already issued expires within an hour.
  • On Claude Team and Enterprise, admins also control which connectors members can use, in Claude's organisation settings.

8. Security

TransportTLS 1.2 or later, with HSTS
IsolationEach workspace is isolated in its own database. Every token is bound to one workspace and one user.
LimitsRequests are rate limited and size limited per connection.

Prompt injection

Uploaded documents are scanned for injected instructions and quarantined when they look hostile. Ask Alia treats retrieved content as data rather than instructions.

Content your team writes into the graph is returned to agents as written, so treat it as you would any shared internal document.

Reporting vulnerabilities

Email [email protected]. Our disclosure details are in /.well-known/security.txt.

9. Example prompts

PromptTools used
"What did we decide about pricing for the Pro plan, and why?"engramic_search, engramic_timeline, engramic_event
"Ask Alia what our current constraints are for the onboarding redesign."ask_alia
"We just agreed to move the launch to March; record that decision against the Launch topic."engramic_record_draft, engramic_record_publish
"Log an open question: who owns customer data deletion requests?"engramic_create_gap

10. Support

Troubleshooting

SymptomWhat to do
The sign-in window did not openRun /mcp in Claude Code, or reconnect in Claude settings.
Tools are missingCheck the connection is enabled for the conversation.
forbidden_roleYour workspace role is viewer. Viewers can use read-only tools except Open Share. Ask an owner to change your role.