Before You Begin
You need:- A Lendflow account with access to the data and actions you want to use.
- An AI client that supports remote HTTP MCP servers.
- For clients that connect by setting a request header, an Integration Token with the MCP Server Tools permission group.
MCP uses your existing Lendflow access. It does not give you access to additional deals, data, or administrative actions. The tools available to you depend on your user role and, when you connect with a token, that token’s permissions.
Lendflow MCP Endpoint
Use the following production endpoint:Connect from Claude
Claude connects to Lendflow by sending you to Lendflow to sign in. You do not need an Integration Token.- Open Claude’s settings and go to Connectors.
- Select Add custom connector.
- Enter a name, such as
Lendflow, and the URLhttps://mcp.api.lendflow.com. - Save the connector and select Connect.
- Sign in to Lendflow in the window that opens, then approve the connection.
Connect from Claude Code
Add the server, then authenticate from inside a session:/mcp in a Claude Code session, select the Lendflow server, and complete the sign-in in your browser. Run /mcp again to confirm the server is connected and see its tools.
What You See When You Sign In
Signing in opens two Lendflow pages in your browser. First, the Lendflow sign-in page, if you do not already have an active session. You can sign in with your Lendflow credentials, or with Okta where your organization uses it. Second, an authorization page titled Authorize followed by the name of your AI client. It shows the account you are signed in as, where you will be redirected, and the permission being requested, which is to use the Lendflow MCP server. Select Authorize to complete the connection, or Cancel to stop.Connect from Cursor
Cursor connects with an Integration Token. Add the following to your Cursor MCP configuration:<integration-token> with the Integration Token you copied from Lendflow, then reload the MCP configuration. Confirm the server shows as connected under Settings → MCP Tools.
Connect from Visual Studio Code
Create.vscode/mcp.json in your workspace. Using an input keeps the token out of source control, because Visual Studio Code prompts for it on first use and stores it securely.
Connect from Windsurf
Open Windsurf settings, go to Cascade → MCP servers, select Add Server → Add custom server, and add:Connect from Another MCP Client
In an MCP client that supports remote HTTP servers:- Add a new custom MCP server.
- Set the server URL to
https://mcp.api.lendflow.com. - Select HTTP Streamable transport.
- Sign in with Lendflow if the client offers it, or add an
Authorizationheader with the valueBearer <integration-token>. - Save the configuration and reconnect the client.
ChatGPT and Codex cannot connect to Lendflow MCP yet. Support for OpenAI clients is in progress.
Verify the Connection
After connecting, ask the client to perform a read-only task, such as:Show my current Lendflow user.List the applications I can access.Show the offers for application <application ID>.What Lendflow tools are available to me?
Available Tools
Your MCP client discovers the current list of tools automatically. The available tools may include actions for:- Applications and workflow stages
- Offers and placements
- Notes and communication history
- Funders and configuration options
- Underwriting
Disconnecting and Revoking Access
Disconnecting a client and revoking its access are two separate actions. If you are removing access because a credential may have been exposed, do both, starting with the revoke. Revoke the access. For a connection you signed in to, remove the authorization in Lendflow so the client can no longer obtain a new session. For an Integration Token, open Profile → Integration Tokens and revoke the token. Revoking takes effect immediately and applies to every client using that token, including copies you have forgotten about. Disconnect the client. Remove the Lendflow server from your AI client’s MCP settings and restart it. This affects only that client, and it does not revoke an Integration Token, which remains valid until you revoke it in Lendflow. Revoking does not undo actions an assistant has already taken. If you are revoking after a mistake, review the applications and notes created or changed during the session.Troubleshooting
The client cannot authenticate
- Confirm that the
Authorizationheader begins withBearer. - Confirm that the complete Integration Token was copied.
- Check whether the token is expired or revoked.
- For a sign-in connection, remove the server from your client and add it again to restart the authorization.
The sign-in page does not appear
Confirm the URL ishttps://mcp.api.lendflow.com with no path after the host name, and that your client supports remote MCP servers with a sign-in flow. Clients that only accept a request header need an Integration Token instead.
A tool or action is missing
- Confirm that your Lendflow role allows the action.
- Confirm that the token includes the required permission.
- Reconnect the MCP client after changing token permissions, so it can discover the tools again.
A request is rejected
Check that required IDs and option values are valid for your account. Ask the client to retrieve current options before retrying an action that uses workflow templates, workflow statuses, or other configured values.The client reaches a request limit
MCP requests are limited to 600 requests per minute per user by default, and an Integration Token can carry its own lower limit. Wait for the limit to reset, or review the token’s rate limit.Security Recommendations
- Prefer signing in with Lendflow over a stored token when your client supports it.
- Use a dedicated Integration Token for each MCP client.
- Grant only the permissions the client needs.
- Set an expiration when practical.
- Revoke tokens and connections that are no longer used.
- Review an AI client’s proposed write action before approving it.
Next steps
MCP Tools
Understand the Lendflow tools available to MCP clients.