How Lendflow MCP Works
When you connect an AI client to Lendflow MCP:- The client authenticates, either by sending you to Lendflow to sign in or by using an Integration Token.
- Lendflow provides the tools available to your account.
- The client selects a tool based on your request.
- Lendflow validates the session or token, permissions, input, and data access.
- The tool returns the result to the client.
What You Can Do
Depending on your role and permissions, Lendflow MCP can help you:- Find and review applications
- Review offers and placements
- Check workflow stages and available options
- Look up funders in your lender network
- View communication history
- Create application and business notes
- Create or update applications
- Update workflow or placement statuses
- Run supported underwriting actions
Two Ways to Connect
Lendflow MCP supports two authentication methods. Which one you use depends on your AI client.Sign in with Lendflow
Clients that support remote MCP servers with a sign-in flow send you to Lendflow to authenticate and approve the connection. Nothing is copied or pasted, and no credential is stored in a configuration file. Use this method with Claude and Claude Code.Integration Token
Clients that connect to a remote MCP server by setting a request header use an Integration Token instead. You create the token in Lendflow once and add it to the client’s configuration. Use this method with Cursor, Visual Studio Code, Windsurf, and other clients that accept a custom header.Both methods act as your Lendflow user and respect the same roles, permissions, and data access rules. The difference is only in how the client proves who you are.
Access and Permissions
Lendflow MCP operates as the user who signed in or who created the Integration Token. For every action:- The session or token must be active.
- An Integration Token must include the required permission.
- The user’s Lendflow role must allow the action.
- The user must have access to the requested client, deal, or resource.
Connecting Lendflow MCP does not grant access to additional data. Users can access only the data and actions already available to their Lendflow account.
Integration Tokens
When your client connects with a request header, Lendflow MCP requires an Integration Token with the MCP Server Tools permission group. Use a dedicated token for each MCP client. This allows you to change permissions, review usage, or revoke one connection without affecting another integration. Create an Integration TokenMCP or Command Bar?
Use the Command Bar when you want to search and work with AI agents inside the Lendflow dashboard. Use Lendflow MCP when you want to connect an external AI client, such as Claude or Cursor, to Lendflow. Both experiences respect your Lendflow permissions, but MCP requires its own sign-in or Integration Token because the client operates outside your dashboard session.MCP or Direct API Integration?
Use MCP when:- An AI client should discover available tools automatically.
- Users want to work with Lendflow through natural-language requests.
- The integration benefits from standardized tool descriptions and inputs.
- You are building a deterministic application workflow.
- Your service needs complete control over requests and responses.
- The integration does not use an MCP-compatible client.
Read and Write Actions
MCP includes both read and write tools. Every tool tells your AI client whether it only reads data or may change it, and most clients ask you to confirm before running a tool that can change something. Before approving a write action:- Review the action the AI client plans to perform.
- Confirm the target application or placement.
- Verify any status, note visibility, or workflow values.
- Approve the action only when the proposed change is correct.
Why Some Reads Ask for Confirmation
A few tools that feel like reads are declared as changing data, so your client may ask you to confirm them. This is intentional and accurate. Reading an application, its workflow stages, its offers, or its available options requires a current workflow snapshot. When an application does not have one yet, or has one built on an earlier version of its workflow, Lendflow creates or updates the snapshot as part of serving the request. That is a genuine write, so the tool declares it rather than hiding it. The affected tools areget_application, get_workflow_stages, get_options, list_application_offers, and check_permission. None of them changes application data, moves a workflow, or contacts anything outside Lendflow.
Current Option Values
Some tools require values configured for your account, such as workflow templates, workflow statuses, or note visibility options. Lendflow MCP provides an options tool that allows the client to retrieve valid values before performing an action. Ask the client to check available options when a request depends on account-specific configuration.How Your Data Flows
When an assistant uses a Lendflow tool, the request travels from your AI client to Lendflow over HTTPS, and the result travels back to your client.- What Lendflow receives. The tool name and the arguments your client selected. Lendflow never receives your credentials for any other service.
- What Lendflow returns. Only the records the tool requested, and only those your user is authorized to see. The same policies, client scoping, and validation that govern the Lendflow API apply unchanged.
- Where the result goes next. Your AI client passes the result to its model provider so the assistant can reason over it. For a hosted assistant, this means Lendflow data, including borrower personal and financial information, is transmitted to that provider. How the provider stores or retains that data is governed by your agreement with them.
- What Lendflow records. MCP tool calls are logged for audit and support in the same way API requests are.
Rate Limits
MCP requests are limited to 600 requests per minute per user by default, matching the Lendflow API. A single tool call consumes budget from both the MCP endpoint and the API route behind it, so a tool-heavy assistant uses the allowance faster than the number of tool calls suggests. An Integration Token can carry its own lower rate limit. Contact your Lendflow representative if you need a higher limit.Get Started
- Connect your MCP client, signing in with Lendflow or creating an Integration Token with the MCP Server Tools permission group.
- Verify the connection with a read-only request.
- Review the available tools and, for a token, add only the permissions you need.
Security Recommendations
- Prefer signing in with Lendflow over a stored token when your client supports it.
- Use a separate Integration Token for each MCP client.
- Grant the minimum required permissions.
- Store tokens in secure client configuration or secret storage.
- Never commit tokens to source control.
- Set an expiration when practical.
- Revoke tokens and connections that are no longer used.
- Review write actions before approving them.
Support
For help with setup, unexpected tool behavior, or access problems, contact Lendflow support at support@lendflow.com, or reach out to your account manager. When reporting a problem, include the AI client and version, the tool that failed, and the error message exactly as your client displayed it. Do not include access tokens or borrower personal information in a support request.Next steps
Connect Lendflow MCP
Connect an AI client to Lendflow using the Model Context Protocol.
MCP Tools
Understand the Lendflow tools available to MCP clients.