> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lendflow.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Lendflow MCP

> Connect external AI clients to Lendflow through the Model Context Protocol.

Lendflow MCP allows compatible AI clients to securely use Lendflow tools and data. It provides a structured way for an AI assistant to find applications, review offers and placements, create notes, update records, and perform other approved actions.

MCP stands for Model Context Protocol, an open standard that allows an AI client to discover and use tools provided by another application.

## How Lendflow MCP Works

When you connect an AI client to Lendflow MCP:

1. The client authenticates, either by sending you to Lendflow to sign in or by using an Integration Token.
2. Lendflow provides the tools available to your account.
3. The client selects a tool based on your request.
4. Lendflow validates the session or token, permissions, input, and data access.
5. The tool returns the result to the client.

The AI client does not connect directly to the Lendflow database. MCP tools use the same application services, validation, and authorization rules as the Lendflow API.

## What You Can Do

Depending on your role and permissions, Lendflow MCP can help you:

* Find and review applications
* Review offers and placements
* Check workflow stages and available options
* Look up funders in your lender network
* View communication history
* Create application and business notes
* Create or update applications
* Update workflow or placement statuses
* Run supported underwriting actions

Your MCP client discovers the current tools automatically. Tools that are not available to your role are not exposed to you.

[View MCP Tools](/lendflow-external/docs/mcp-tools)

## Two Ways to Connect

Lendflow MCP supports two authentication methods. Which one you use depends on your AI client.

### Sign in with Lendflow

Clients that support remote MCP servers with a sign-in flow send you to Lendflow to authenticate and approve the connection. Nothing is copied or pasted, and no credential is stored in a configuration file.

Use this method with Claude and Claude Code.

### Integration Token

Clients that connect to a remote MCP server by setting a request header use an [Integration Token](/lendflow-external/docs/integration-tokens) instead. You create the token in Lendflow once and add it to the client's configuration.

Use this method with Cursor, Visual Studio Code, Windsurf, and other clients that accept a custom header.

<Note>
  Both methods act as your Lendflow user and respect the same roles, permissions, and data access rules. The difference is only in how the client proves who you are.
</Note>

[Connect Lendflow MCP](/lendflow-external/docs/connect-lendflow-mcp)

## Access and Permissions

Lendflow MCP operates as the user who signed in or who created the Integration Token.

For every action:

* The session or token must be active.
* An Integration Token must include the required permission.
* The user's Lendflow role must allow the action.
* The user must have access to the requested client, deal, or resource.

<Note>
  Connecting Lendflow MCP does not grant access to additional data. Users can access only the data and actions already available to their Lendflow account.
</Note>

Some tools are available only to users with specific roles. Two users connected to the same MCP endpoint may therefore see different tools and results.

## Integration Tokens

When your client connects with a request header, Lendflow MCP requires an Integration Token with the **MCP Server Tools** permission group.

Use a dedicated token for each MCP client. This allows you to change permissions, review usage, or revoke one connection without affecting another integration.

[Create an Integration Token](/lendflow-external/docs/integration-tokens)

## MCP or Command Bar?

Use the [Command Bar](/lendflow-external/docs/command-bar) when you want to search and work with AI agents inside the Lendflow dashboard.

Use Lendflow MCP when you want to connect an external AI client, such as Claude or Cursor, to Lendflow.

Both experiences respect your Lendflow permissions, but MCP requires its own sign-in or Integration Token because the client operates outside your dashboard session.

## MCP or Direct API Integration?

Use MCP when:

* An AI client should discover available tools automatically.
* Users want to work with Lendflow through natural-language requests.
* The integration benefits from standardized tool descriptions and inputs.

Use the Lendflow API directly when:

* You are building a deterministic application workflow.
* Your service needs complete control over requests and responses.
* The integration does not use an MCP-compatible client.

MCP tools use Lendflow API capabilities behind the scenes. The appropriate choice depends on how the integration will be operated.

## Read and Write Actions

MCP includes both read and write tools. Every tool tells your AI client whether it only reads data or may change it, and most clients ask you to confirm before running a tool that can change something.

Before approving a write action:

1. Review the action the AI client plans to perform.
2. Confirm the target application or placement.
3. Verify any status, note visibility, or workflow values.
4. Approve the action only when the proposed change is correct.

<Warning>
  Only grant write permissions that the MCP client needs. Revoke the Integration Token or the connection immediately if a client or token may have been compromised.
</Warning>

### Why Some Reads Ask for Confirmation

A few tools that feel like reads are declared as changing data, so your client may ask you to confirm them. This is intentional and accurate.

Reading an application, its workflow stages, its offers, or its available options requires a current workflow snapshot. When an application does not have one yet, or has one built on an earlier version of its workflow, Lendflow creates or updates the snapshot as part of serving the request. That is a genuine write, so the tool declares it rather than hiding it.

The affected tools are `get_application`, `get_workflow_stages`, `get_options`, `list_application_offers`, and `check_permission`. None of them changes application data, moves a workflow, or contacts anything outside Lendflow.

## Current Option Values

Some tools require values configured for your account, such as workflow templates, workflow statuses, or note visibility options.

Lendflow MCP provides an options tool that allows the client to retrieve valid values before performing an action. Ask the client to check available options when a request depends on account-specific configuration.

## How Your Data Flows

When an assistant uses a Lendflow tool, the request travels from your AI client to Lendflow over HTTPS, and the result travels back to your client.

* **What Lendflow receives.** The tool name and the arguments your client selected. Lendflow never receives your credentials for any other service.
* **What Lendflow returns.** Only the records the tool requested, and only those your user is authorized to see. The same policies, client scoping, and validation that govern the Lendflow API apply unchanged.
* **Where the result goes next.** Your AI client passes the result to its model provider so the assistant can reason over it. For a hosted assistant, this means Lendflow data, including borrower personal and financial information, is transmitted to that provider. How the provider stores or retains that data is governed by your agreement with them.
* **What Lendflow records.** MCP tool calls are logged for audit and support in the same way API requests are.

Lendflow deals contain data originally sourced from credit bureaus, bank data aggregators, and identity and business verification providers, under the agreements already in place for your account. Reading a deal can return that data, and running underwriting causes those providers to run. MCP does not add a new provider or a new data-sharing relationship.

<Warning>
  Review your agreement with your AI client's model provider before connecting a production Lendflow account.
</Warning>

## Rate Limits

MCP requests are limited to 600 requests per minute per user by default, matching the Lendflow API. A single tool call consumes budget from both the MCP endpoint and the API route behind it, so a tool-heavy assistant uses the allowance faster than the number of tool calls suggests.

An Integration Token can carry its own lower rate limit. Contact your Lendflow representative if you need a higher limit.

## Get Started

1. [Connect your MCP client](/lendflow-external/docs/connect-lendflow-mcp), signing in with Lendflow or creating an [Integration Token](/lendflow-external/docs/integration-tokens) with the **MCP Server Tools** permission group.
2. Verify the connection with a read-only request.
3. Review the available tools and, for a token, add only the permissions you need.

## Security Recommendations

* Prefer signing in with Lendflow over a stored token when your client supports it.
* Use a separate Integration Token for each MCP client.
* Grant the minimum required permissions.
* Store tokens in secure client configuration or secret storage.
* Never commit tokens to source control.
* Set an expiration when practical.
* Revoke tokens and connections that are no longer used.
* Review write actions before approving them.

## Support

For help with setup, unexpected tool behavior, or access problems, contact Lendflow support at [support@lendflow.com](mailto:support@lendflow.com), or reach out to your account manager.

When reporting a problem, include the AI client and version, the tool that failed, and the error message exactly as your client displayed it. Do not include access tokens or borrower personal information in a support request.

## Next steps

<Card title="Connect Lendflow MCP" icon="plug" horizontal href="/lendflow-external/docs/connect-lendflow-mcp">
  Connect an AI client to Lendflow using the Model Context Protocol.
</Card>

<Card title="MCP Tools" icon="screwdriver-wrench" horizontal href="/lendflow-external/docs/mcp-tools">
  Understand the Lendflow tools available to MCP clients.
</Card>
