ArxDeck
Integrations

MCP

ArxDeck MCP server — tools, authentication, and agent configuration.

MCP (ArxDeck server)

The ArxDeck MCP server exposes HTTP JSON-RPC tools so agents can read and mutate project data during an active agent run or chat turn. Tool access is scoped per agent via an allowlist; calls are audited for ArxDeck-native tools.

What agents can do with MCP

Tool groups include:

  • Tickets — read and update tickets, comments, search
  • Agent run — report outcomes, request user input, create pull requests
  • Proposals — propose ticket drafts, comments, knowledge changes; get_proposal_status, list_proposal_status, and reject_proposal for the current chat or run. reject_proposal preserves business error text (already approved/rejected, superseded, or the actual state). Configuration @ref: dependencies chain module actions, project templates (set_manifest / set_setup_action fields), and project module installs within the same chat or run. Content module update proposals accept partial payloads; omitted fields are preserved. Comment proposals validate the target ticket before creation. propose_knowledge_workflow uses action-specific input schemas (workflowAction + fields per action). Successful propose_* calls may return warnings[] for ignored fields that are not part of the tool schema.
  • Knowledge — list types, search items, read pinned context; get_project_info for integration values (content ref/URL, capability flags, publish URLs)
  • Chat — read conversations (get_conversation); add or mark stale extraction candidates in the current chat run (update_extraction_queue, omitted when platform chat extraction is disabled)
  • Scheduled tasks — read and update task state when allowed
  • Deployments — read get_deployment_status and get_deployment_run_logs; configuration mutations via propose_deployment_config only
  • Configuration — propose and discovery tools for agents, workflows, scheduled tasks, skills, content modules, project settings, GitHub, webhooks, feedback, publish, and more (get_config_permissions, propose_*_config, get_*_config, list_*_config, list_mcp_tools_config, list_agent_provider_models_config, list_platform_modules_config, list_catalog_context, search_content_modules). Callable when allowlisted on the agent and the current actor is authorized — ArxDeck Helper is the curated default, not a runtime privilege boundary.

External organization-registered MCP servers can attach to agents with a separate org tool allowlist. Those calls are not audited inside ArxDeck in v1.

When MCP is available

  • Cursor Cloud and local-agent ticket runs mint a run-scoped token automatically when MCP is enabled on the agent
  • Project chat turns with MCP-enabled agents receive run-scoped tokens for the chat run
  • Project tokens (admin-created) support discovery and tools/list but are not a substitute for run-bound work

MCP tools are unavailable after a run reaches waiting_for_input or a terminal status.

Viewing MCP calls on a message

On agent-authored project chat messages, ticket agent comments, and scheduled-task run agent comments, use the plug icon on the message to open the MCP tool-call list for that run or turn. The popup stays within the visible browser window, scrolls when there are many calls, and opens above the icon when there is not enough room below.

Setup & configuration

  1. Open Settings → Agents → [agent] → MCP.
  2. Enable ArxDeck MCP and select allowed tool groups.
  3. Optionally attach external MCP servers registered under Organization → MCP servers.
  4. For Cursor Cloud ticket automations, no manual Cursor dashboard MCP setup is required — ArxDeck injects inline MCP on launch when enabled.

Organization admins register external servers with HTTPS URLs and credentials or OAuth connect flows.

Technical details

TopicDetail
Endpointhttps://workspace.arxdeck.ai/api/mcp (your organization's ArxDeck dashboard origin)
ProtocolHTTP JSON-RPC: GET returns server info; POST handles initialize, tools/list, tools/call
Run-scoped tokenBearer token minted per run (prefix arx_mcp_). Passed once to the provider; only a hash is stored. Revoked when the run ends (or on launch failure). For Cursor Cloud chat, the token stays valid after SSE transport loss while the provider run is still active. Run context is derived from the token — tool arguments do not include run IDs.
Integration discoveryCall get_project_info with {} during agent runs to read projectRef, contentServiceUrl, capability flags, and deployment publicUrl values. Use this instead of inventing env-var or build-time configuration for static sites.
Project tokenCreated on Settings → ArxDeck MCP Audit (project admins). Shown once at creation. Suitable for tools/list and manual discovery; run-bound agent work still uses per-run tokens.
Archived projectsMCP calls are rejected for archived projects until unarchived.

Do not publish tokens, encryption keys, or raw Bearer values in tickets or documentation.