Connecting AI tools (MCP)

Letting Claude, ChatGPT and similar clients work with your organisation's data in The Cards.

Permission
Organisation administrator to issue tokens

The Cards exposes a Model Context Protocol server. MCP is an open standard that lets an AI client such as Claude Code, Claude Desktop or ChatGPT call tools in another system. Connecting one means you can ask your own assistant questions like "what did we report for energy consumption last year" and have it read the answer out of The Cards.

How access works

An MCP connection is authenticated with a personal access token created in Settings → MCP. The token acts as the person who created it: it can never see or do more than that user can in the application. Narrowing scopes narrows it further; it never widens.

The MCP tab in Settings before any token exists. A short explanation sits above an empty table with columns for name, owner, token, scopes, last used, expires, updated and status. Buttons for Connect a client and Create token sit at the top right.
The MCP tab before the first token is issued. Every token created here is listed with its owner and scopes, which is how you tell later what a given client can reach.

Creating a token

  1. Open Settings → MCP and choose Create token

    Give it a name that says which client it is for, so it can be recognised and revoked later.

  2. Pick the scopes

    Choose the umbrella scopes or specific ones. See MCP scopes.

  3. Restrict it to reports, if useful

    Either all reports I can read, which automatically includes reports created later, or only selected reports, a fixed list that never grows.

  4. Set an expiry

    30, 90 or 365 days, or never. Prefer a real expiry.

  5. Copy the token

    It is shown once. Copy it into your client straight away; it cannot be retrieved afterwards.

Managing tokens

The MCP tab lists every token with its owner, scopes, expiry and when it was last used. Tokens can be edited (scopes, report restriction, expiry) and revoked. Revoking takes effect immediately and cannot be undone.

Write access

Read scopes let a client look. Write scopes let it change report content directly, with no approval step: the client edits, and the change is in the report.

N

The Cards is a product developed by ICONS OF.

Visit http://www.iconsof.se to read more about us and our vision.

Partner
Microsoft startups
Copyright © 2026 TheCards.eu