Connect an AI assistant
Give Claude, ChatGPT or your own agent access to Nucleo with the MCP connector, with each person's own permissions.
How it works
Nucleo runs one remote Model Context Protocol server at https://mcp.nucleoplatform.com. An AI client connected to it sees the tools of every Nucleo module the person can use — Brain, Catalog, Commerce, Intelligence — in the company they choose, with their own roles and permissions. No tool deletes data.
There are no keys to copy: the person signs in to Nucleo from the AI client and approves a consent screen. The client gets an OAuth access token that only works on the AI tools.
Connect Claude or ChatGPT
Claude (web, desktop and mobile apps):
- In Claude, go to Settings > Connectors and select Add custom connector.
- Name it
Nucleoand enter the URLhttps://mcp.nucleoplatform.com. - Select Connect, sign in to Nucleo and approve access.
ChatGPT (developer mode):
- In ChatGPT, go to Settings > Connectors > Advanced and turn on developer mode.
- Select Create, enter the MCP server URL
https://mcp.nucleoplatform.comand choose OAuth authentication. - Sign in to Nucleo and approve access.
If the person belongs to more than one company, the assistant can list them and switch with the connector's own tools before working.
Build your own MCP client
Any MCP client that supports remote servers with OAuth works. The server speaks protocol version 2025-06-18 over Streamable HTTP with JSON responses (no server-sent stream). The flow your client runs:
POST https://mcp.nucleoplatform.comwithout a token →401with aWWW-Authenticateheader pointing to the protected-resource metadata (RFC 9728).- The metadata names
https://auth.nucleoplatform.comas authorization server; read its metadata at/.well-known/oauth-authorization-server. - Register the client at
/oauth/register(RFC 7591) with yourredirect_uris. - Run the authorization code flow with PKCE (S256); the person signs in and consents.
- Exchange the code at
/oauth/token, then sendAuthorization: Bearer <token>on every MCP request. Refresh with the refresh token when it expires.
curl -X POST https://auth.nucleoplatform.com/oauth/register \
-H "Content-Type: application/json" \
-d '{
"client_name": "Acme Ops Assistant",
"redirect_uris": ["https://assistant.acme.example/oauth/callback"],
"token_endpoint_auth_method": "none"
}'curl -X POST https://mcp.nucleoplatform.com \
-H "Authorization: Bearer $NUCLEO_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc": "2.0", "id": 1, "method": "tools/list"}'Every call to /oauth/register creates a new client: register once and store the client_id. Redirect URIs must be https, except loopback addresses for local tools.
Call the module tools without MCP
If you run your own agent runtime and do not need MCP, the same tools are available as plain HTTP on each module: GET /api/v1/ai-tools lists them with their JSON Schema, POST /api/v1/ai-tools/{name} runs one. Use the same OAuth token and name the company in X-Nucleo-Company. See AI Tools.
Permissions and writes
- The assistant can do only what the person can do in Nucleo, in the active company.
- Commerce and Intelligence tools are read-only. Brain and Catalog have write tools, marked as such in the tool list.
- Catalog applies only small, reversible changes from an AI client. Larger ones — bulk changes, publishing, imports, deletions — come back as a preview and the person confirms them inside Nucleo.
- Tokens issued to AI clients work only on the AI tools: they cannot call any other Nucleo API.
- To disconnect, remove the connector in the AI client; the token can also be revoked with
POST https://auth.nucleoplatform.com/api/auth/revoke.