Privacy
What Everyn MCP stores, redacts, and never puts in tool text or public search.
The public production MCP endpoint is live at https://mcp.everyn.ai/mcp. Configure a host with that Streamable HTTP URL and complete WorkOS OAuth.
MCP uses the same Dataset, Job, Run, and export records as the rest of Everyn. It does not create a parallel data store.
Organization boundary
Every call is authorized for the selected organization only. Cross-organization existence is not disclosed. Missing or unauthorized resources look like not_found, not a map of other workspaces.
Organization selection comes from consent, not from model input.
Credentials and transfer descriptors
Access tokens, refresh tokens, and signed upload/download descriptors must never appear in:
- tool
textfallbacks - later tool inputs
- logs or traces
- support references
- chat transcripts you write back to the user
The signed transfer descriptor is the only credential-like tool-output exception, and only in its dedicated structured field.
Support references
When a receipt includes a support reference, it is a short operational token. It never embeds row content, credentials, descriptors, or raw provider payloads.
Do not email Dataset rows, signed URLs, or API keys to support. Use Help and help@everyn.ai.
Public docs search
search_docs searches only published Everyn Docs and Help. It never indexes repository-private planning, runbooks, credentials, or company knowledge.
Product policies
MCP follows the same Privacy Policy and Terms of Service as the rest of Everyn. MCP settings never reveal tokens.