For technical teams · Agents and MCP
One MCP server. Every assistant.
Muvia exposes a remote MCP server: Claude, ChatGPT, Microsoft Copilot and Cursor connect to the same address. Access goes through OAuth 2.1 with the Muvia login, the assistant works with the user's own permissions, and every call is logged.
- OAuth 2.1 + PKCE
- RFC 7591
- RFC 8707
- RFC 9207
Client configuration
{
"mcpServers": {
"muvia": {
"url": "https://api.muviabi.com/mcp/v1"
}
}
}- POST /mcp/v1 401 · resource_metadata
- POST /register · client registered
- Muvia login + consent · code
- POST /token · mvo_at_… (1 h)
- tools/call whoami · your company, your user
How an assistant connects.
The protocol is the same for every client. Only the place the connection starts from changes: the user never pastes a password into the assistant.
01 · discovery
The assistant knocks
The server answers 401 and says where to authenticate. The client registers itself through dynamic client registration.
02 · login
The user signs in to Muvia
With the usual login: password, TOTP code or passkey, as the company's policy requires. A user who works for several companies picks one.
03 · consent
They decide what to grant
The page shows the client's name, whether it is verified and where it redirects. Write and SQL can be unticked.
04 · work
The assistant uses the tools
With a one-hour token, renewed by rotation. If a refresh token is reused, the connection revokes itself.
- PKCE S256 required
- Without it, the request is refused.
- Opaque tokens, stored as hashes
- In clear text they exist only in the response that creates them.
- Bound to the Muvia server
- They are valid for this resource only, nowhere else.
- Exact-match redirects
- HTTPS, with loopback for desktop clients.
Three permissions, chosen by the user.
Each tool declares the Muvia permission it needs. The permission granted to the assistant only sets the ceiling.
| Scope | What the user sees at consent | Notes |
|---|---|---|
| muvia.read | Read projects, signals, alarms, flows, analyses and documents | The default |
| muvia.sql | Run read-only SQL queries on project data | Only applies if the user's role allows running queries |
| muvia.write | Launch flows, create analyses and dashboards, attach notes and documents | Every write asks the user for confirmation |
Never delegated, by any scope: company administration, management of nodes and sources, acknowledging alarms, custom functions and the superadmin's powers.
The assistant can never do more than the user.
A connection is a delegation: one user, one company, one assistant. What the assistant can do is recomputed on every call.
- The user's current rolesintersected with
- Granted scopesintersected with
- The company's modulesintersected with
- Admin opt-in
- equalsWhat the assistant can do
- The company is not an argument
- It comes from the connection, never from the request. Another company's project answers as if it did not exist.
- When roles change, so does the assistant
- Remove a role from the user and the assistant loses it on the next call. Once the user leaves the company, they must sign in again.
- No shortcuts for superadmins
- Only someone with a role in the company can connect. An impersonation session cannot approve a connection.
The administrator decides.
- Off until they turn it on
- It takes the AI Connectors module and the administrator's opt-in. If either is missing, the server refuses.
- Which assistants are allowed
- Verified clients only, by default; all of them; or an exact list.
- Immediate revocation
- No cache: a revoked connection stops working on the next call.
Everything is on record.
- 08:14oauth_grant_created · Copilot
- 08:15tool_call · query_sql · Copilot
- 11:02oauth_grant_revoked · reason=admin
Registered clients, connections created, updated and revoked with the reason, and every tool call with the client and the connection that made it.
Where you connect from.
Claude
Remote connector, with OAuth login.
ChatGPT
Remote connector, with OAuth login.
Microsoft Copilot
Connector for Copilot Studio.
Cursor and desktop clients
OAuth login with a local redirect on the user's computer.
Integrations and scripts
With no user present: an
mvk_API key on the same server, with its own permissions and its own company. The module and the administrator's opt-in apply here too.
Connect your assistant.
The step-by-step guide, the protocol references and the examples are on the developer portal.