MCP

Privacy

What Everyn MCP stores, redacts, and never puts in tool text or public search.

The public production MCP endpoint is live at https://mcp.everyn.ai/mcp. Configure a host with that Streamable HTTP URL and complete WorkOS OAuth.

MCP uses the same Dataset, Job, Run, and export records as the rest of Everyn. It does not create a parallel data store.

Organization boundary

Every call is authorized for the selected organization only. Cross-organization existence is not disclosed. Missing or unauthorized resources look like not_found, not a map of other workspaces.

Organization selection comes from consent, not from model input.

Credentials and transfer descriptors

Access tokens, refresh tokens, and signed upload/download descriptors must never appear in:

  • tool text fallbacks
  • later tool inputs
  • logs or traces
  • support references
  • chat transcripts you write back to the user

The signed transfer descriptor is the only credential-like tool-output exception, and only in its dedicated structured field.

Support references

When a receipt includes a support reference, it is a short operational token. It never embeds row content, credentials, descriptors, or raw provider payloads.

Do not email Dataset rows, signed URLs, or API keys to support. Use Help and help@everyn.ai.

search_docs searches only published Everyn Docs and Help. It never indexes repository-private planning, runbooks, credentials, or company knowledge.

Product policies

MCP follows the same Privacy Policy and Terms of Service as the rest of Everyn. MCP settings never reveal tokens.