Engramic MCP server
Documentation for administrators and developers.
Last updated: 1 October 2026
1. Overview
Engramic is the knowledge graph a team authors: its decisions, goals, constraints and gaps. The Engramic MCP server lets AI agents read that graph and record to it, so an agent working in Claude, Cursor or another MCP client starts from what your team has already decided.
This page is for the people who set up and approve the connector: workspace owners, IT administrators and security reviewers. It describes how the connector signs in, what it can do, where data goes and what administrators can control.
Requirements
- An Engramic account and a workspace.
- The connector works on every Engramic plan, including Free.
2. Connect
The server is remote and uses streamable HTTP. There is nothing to install or host.
https://api.engramic.ai/mcpClaude web and desktop
Go to Settings, then Connectors, then Add custom connector, and enter the server URL above. On Claude Team and Enterprise plans, an owner or admin adds it under Organization settings, then Connectors.
Claude Code
claude mcp add --transport http --scope user engramic https://api.engramic.ai/mcp/mcpRun /mcp inside Claude Code to sign in. We also recommend the Engramic plugin, which records key decisions from Claude Code sessions. Steps are on the Engramic for Claude page.
Other clients
Setup steps for Cursor, VS Code, Codex and Windsurf are at app.engramic.ai/connect.
3. Authentication
The server uses OAuth 2.1 with PKCE (S256 only) and dynamic client registration. There are no API keys or tokens to paste.
At sign-in, the user picks the workspace and who the connection acts as: themselves, or a named agent they manage. Each connection is bound to one workspace. The consent screen shows the domain the app will return you to, and flags apps Engramic doesn't recognise.
| Standard | OAuth 2.1, PKCE with S256 only, dynamic client registration |
|---|---|
| Protected resource metadata (RFC 9728) | https://api.engramic.ai/.well-known/oauth-protected-resource |
| Authorisation server metadata (RFC 8414) | https://api.engramic.ai/.well-known/oauth-authorization-server |
| Authorisation codes | Last 10 minutes and are single use |
| Access tokens | Last 1 hour |
| Refresh tokens | Last 30 days, rotate on every use and are stored hashed |
| Revocation | Supported (RFC 7009) |
| Workspace binding | Each connection is bound to one workspace |
4. Permissions
A connection acts with the signed-in user's own workspace role, checked on every request. Owners and contributors can use read and write tools. Viewers can use every read-only tool except Open Share.
Every write appears on the workspace timeline, credited to the person or named agent that made it.
No tool deletes anything. The Update tools are flagged destructive because an update replaces a field's previous value.
5. Tools reference
Read-only tools do not change workspace content. Write tools create or change content and need an owner or contributor role.
| Tool | Title | What it does | Type |
|---|---|---|---|
engramic_search | Search Engramic | Find topics and timeline events by text. | Read-only |
ask_alia | Ask Alia | Ask one question and get one answer synthesised from the workspace by Engramic’s assistant, Alia. | Read-only |
engramic_summary | Workspace Summary | The caller’s identity and a workspace overview. | Read-only |
engramic_topic | Browse Topic | Browse the topic graph one level at a time. | Read-only |
engramic_timeline | Query Timeline | Decisions, actions, events and discoveries, filtered by type, actor, topic or date. | Read-only |
engramic_event | Get Event | One timeline event in full. | Read-only |
engramic_open_share | Open Share | Open a shared topic snapshot by its ID. Each open is logged (not available to viewers). | Read-only |
engramic_record_draft | Draft Record | Stage a decision, action, event or discovery and get the topic’s context first. | Write |
engramic_record_publish | Publish Record | Publish a staged record to the timeline. | Write |
engramic_create_conceptengramic_create_goalengramic_create_gapengramic_create_constraintengramic_create_resource | Create Concept, Create Goal, Create Gap, Create Constraint, Create Resource | Create a topic of that type. | Write |
engramic_update_conceptengramic_update_goalengramic_update_gapengramic_update_constraintengramic_update_resource | Update Concept, Update Goal, Update Gap, Update Constraint, Update Resource | Change a topic’s fields. | Write, destructive |
6. Data handling
What passes through the connector
The workspace's topics, timeline and shares, as read and written by the tools above.
Hosting, encryption at rest and backups
Each workspace has its own separate database. Engramic's servers run on AWS in London, UK (eu-west-2). Cloudflare delivers the website and app.
| Hosting | AWS, London, UK (eu-west-2) |
|---|---|
| Encryption at rest | Data is stored on encrypted volumes (AWS EBS encryption) |
| Backups | Automated hourly backups using AWS Backup |
Third parties
Only Ask Alia sends data outside Engramic. It sends the relevant workspace content and the question to Anthropic's API to generate the answer. No other tool calls an AI model.
Engramic uses Anthropic's API under Anthropic's standard commercial terms, under which Anthropic does not use API inputs or outputs to train its models.
Your content is not used to train third-party AI models. It is processed only to produce the response you asked for.
Retention
Deleting a workspace archives it, and it is permanently deleted after 30 days. For account data and deletion requests, see the privacy policy or email [email protected].
7. Admin controls
- Owners invite members, set roles, and deactivate or remove members.
- Deactivating or removing a member ends their connector access on their next request.
- Users see and revoke their connections under Account, then Connected apps. Revoking deletes that connection's refresh tokens at once. An access token already issued expires within an hour.
- On Claude Team and Enterprise, admins also control which connectors members can use, in Claude's organisation settings.
8. Security
| Transport | TLS 1.2 or later, with HSTS |
|---|---|
| Isolation | Each workspace is isolated in its own database. Every token is bound to one workspace and one user. |
| Limits | Requests are rate limited and size limited per connection. |
Prompt injection
Uploaded documents are scanned for injected instructions and quarantined when they look hostile. Ask Alia treats retrieved content as data rather than instructions.
Content your team writes into the graph is returned to agents as written, so treat it as you would any shared internal document.
Reporting vulnerabilities
Email [email protected]. Our disclosure details are in /.well-known/security.txt.
9. Example prompts
| Prompt | Tools used |
|---|---|
| "What did we decide about pricing for the Pro plan, and why?" | engramic_search, engramic_timeline, engramic_event |
| "Ask Alia what our current constraints are for the onboarding redesign." | ask_alia |
| "We just agreed to move the launch to March; record that decision against the Launch topic." | engramic_record_draft, engramic_record_publish |
| "Log an open question: who owns customer data deletion requests?" | engramic_create_gap |
10. Support
- General and privacy questions: [email protected]
- Security reports: [email protected]
- Privacy policy and Terms and conditions
Troubleshooting
| Symptom | What to do |
|---|---|
| The sign-in window did not open | Run /mcp in Claude Code, or reconnect in Claude settings. |
| Tools are missing | Check the connection is enabled for the conversation. |
forbidden_role | Your workspace role is viewer. Viewers can use read-only tools except Open Share. Ask an owner to change your role. |