> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lendflow.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Lendflow MCP

> Connect an external AI client to Lendflow using the Model Context Protocol.

Lendflow MCP allows compatible AI clients to securely work with the Lendflow data and actions available to your account. Depending on your permissions, you can use it to find applications, review offers and placements, create notes, update records, and perform other Lendflow tasks.

MCP stands for Model Context Protocol, an open standard that allows an AI client to discover and use tools provided by another application.

## Before You Begin

You need:

* A Lendflow account with access to the data and actions you want to use.
* An AI client that supports remote HTTP MCP servers.
* For clients that connect by setting a request header, an [Integration Token](/lendflow-external/docs/integration-tokens) with the **MCP Server Tools** permission group.

<Note>
  MCP uses your existing Lendflow access. It does not give you access to additional deals, data, or administrative actions. The tools available to you depend on your user role and, when you connect with a token, that token's permissions.
</Note>

## Lendflow MCP Endpoint

Use the following production endpoint:

```text theme={"system"}
https://mcp.api.lendflow.com
```

The server uses HTTP Streamable transport. Enter the address exactly as shown, with no path after the host name.

## Connect from Claude

Claude connects to Lendflow by sending you to Lendflow to sign in. You do not need an Integration Token.

1. Open Claude's settings and go to **Connectors**.
2. Select **Add custom connector**.
3. Enter a name, such as `Lendflow`, and the URL `https://mcp.api.lendflow.com`.
4. Save the connector and select **Connect**.
5. Sign in to Lendflow in the window that opens, then approve the connection.

Claude lists the Lendflow tools once the connection completes.

## Connect from Claude Code

Add the server, then authenticate from inside a session:

```bash theme={"system"}
claude mcp add --transport http lendflow https://mcp.api.lendflow.com
```

Run `/mcp` in a Claude Code session, select the Lendflow server, and complete the sign-in in your browser. Run `/mcp` again to confirm the server is connected and see its tools.

## What You See When You Sign In

Signing in opens two Lendflow pages in your browser.

First, the Lendflow sign-in page, if you do not already have an active session. You can sign in with your Lendflow credentials, or with Okta where your organization uses it.

Second, an authorization page titled **Authorize** followed by the name of your AI client. It shows the account you are signed in as, where you will be redirected, and the permission being requested, which is to use the Lendflow MCP server. Select **Authorize** to complete the connection, or **Cancel** to stop.

<Warning>
  Only approve an authorization page that names an AI client you recognize and are actively connecting. If a page appears unexpectedly, select **Cancel**.
</Warning>

## Connect from Cursor

Cursor connects with an Integration Token. Add the following to your Cursor MCP configuration:

```json theme={"system"}
{
  "mcpServers": {
    "lendflow": {
      "url": "https://mcp.api.lendflow.com",
      "transport": "http",
      "headers": {
        "Authorization": "Bearer <integration-token>"
      }
    }
  }
}
```

Replace `<integration-token>` with the Integration Token you copied from Lendflow, then reload the MCP configuration. Confirm the server shows as connected under **Settings → MCP Tools**.

<Warning>
  Do not commit a configuration file containing your token to source control. Use a local configuration or your MCP client's secure secret storage when available.
</Warning>

## Connect from Visual Studio Code

Create `.vscode/mcp.json` in your workspace. Using an input keeps the token out of source control, because Visual Studio Code prompts for it on first use and stores it securely.

```json theme={"system"}
{
  "inputs": [
    {
      "type": "promptString",
      "id": "lendflow-token",
      "description": "Lendflow Integration Token",
      "password": true
    }
  ],
  "servers": {
    "lendflow": {
      "type": "http",
      "url": "https://mcp.api.lendflow.com",
      "headers": {
        "Authorization": "Bearer ${input:lendflow-token}"
      }
    }
  }
}
```

## Connect from Windsurf

Open Windsurf settings, go to **Cascade → MCP servers**, select **Add Server → Add custom server**, and add:

```json theme={"system"}
{
  "mcpServers": {
    "lendflow": {
      "serverUrl": "https://mcp.api.lendflow.com",
      "headers": {
        "Authorization": "Bearer <integration-token>"
      }
    }
  }
}
```

## Connect from Another MCP Client

In an MCP client that supports remote HTTP servers:

1. Add a new custom MCP server.
2. Set the server URL to `https://mcp.api.lendflow.com`.
3. Select HTTP Streamable transport.
4. Sign in with Lendflow if the client offers it, or add an `Authorization` header with the value `Bearer <integration-token>`.
5. Save the configuration and reconnect the client.

The exact settings names vary by client.

<Note>
  ChatGPT and Codex cannot connect to Lendflow MCP yet. Support for OpenAI clients is in progress.
</Note>

## Verify the Connection

After connecting, ask the client to perform a read-only task, such as:

* `Show my current Lendflow user.`
* `List the applications I can access.`
* `Show the offers for application <application ID>.`
* `What Lendflow tools are available to me?`

Start with a read-only request before asking the client to create or update data.

Your client may ask you to confirm a request that only reads an application. This is expected, and the [Overview](/lendflow-external/docs/mcp-overview) explains why.

## Available Tools

Your MCP client discovers the current list of tools automatically. The available tools may include actions for:

* Applications and workflow stages
* Offers and placements
* Notes and communication history
* Funders and configuration options
* Underwriting

Some tools are restricted to specific user roles. For actions that require a current option value, such as a workflow status, the MCP client can use Lendflow's options tool to retrieve values available to your account.

## Disconnecting and Revoking Access

Disconnecting a client and revoking its access are two separate actions. If you are removing access because a credential may have been exposed, do both, starting with the revoke.

**Revoke the access.** For a connection you signed in to, remove the authorization in Lendflow so the client can no longer obtain a new session. For an Integration Token, open **Profile → Integration Tokens** and revoke the token. Revoking takes effect immediately and applies to every client using that token, including copies you have forgotten about.

**Disconnect the client.** Remove the Lendflow server from your AI client's MCP settings and restart it. This affects only that client, and it does not revoke an Integration Token, which remains valid until you revoke it in Lendflow.

Revoking does not undo actions an assistant has already taken. If you are revoking after a mistake, review the applications and notes created or changed during the session.

## Troubleshooting

### The client cannot authenticate

* Confirm that the `Authorization` header begins with `Bearer `.
* Confirm that the complete Integration Token was copied.
* Check whether the token is expired or revoked.
* For a sign-in connection, remove the server from your client and add it again to restart the authorization.

### The sign-in page does not appear

Confirm the URL is `https://mcp.api.lendflow.com` with no path after the host name, and that your client supports remote MCP servers with a sign-in flow. Clients that only accept a request header need an Integration Token instead.

### A tool or action is missing

* Confirm that your Lendflow role allows the action.
* Confirm that the token includes the required permission.
* Reconnect the MCP client after changing token permissions, so it can discover the tools again.

### A request is rejected

Check that required IDs and option values are valid for your account. Ask the client to retrieve current options before retrying an action that uses workflow templates, workflow statuses, or other configured values.

### The client reaches a request limit

MCP requests are limited to 600 requests per minute per user by default, and an Integration Token can carry its own lower limit. Wait for the limit to reset, or review the token's rate limit.

## Security Recommendations

* Prefer signing in with Lendflow over a stored token when your client supports it.
* Use a dedicated Integration Token for each MCP client.
* Grant only the permissions the client needs.
* Set an expiration when practical.
* Revoke tokens and connections that are no longer used.
* Review an AI client's proposed write action before approving it.

## Next steps

<Card title="MCP Tools" icon="screwdriver-wrench" horizontal href="/lendflow-external/docs/mcp-tools">
  Understand the Lendflow tools available to MCP clients.
</Card>
