# Connect an AI client with MCP (https://docs.getaviato.com/integrations/mcp)



## Use the database agent's URL [#use-the-database-agents-url]

Aviato exposes Streamable HTTP MCP at:

```text
https://agent.example.com/mcp
```

Use your database agent's public URL, not the dashboard or control-plane URL. Your MCP client must be able to reach it over HTTPS and support the advertised OAuth flow.

## Authorize the connection [#authorize-the-connection]

Add the endpoint in your client's remote MCP settings and complete the sign-in and consent flow. Start with `aviato:read`. Request `aviato:write` only when the client needs to change records or execute actions.

An OAuth scope does not override the connecting user's permissions. A read-only connection stays read-only even if that user can edit records in the dashboard.

Do not paste the deployment agent token into an MCP client. It is intended for agent-to-control-plane communication.

## Try a read first [#try-a-read-first]

Ask the client to list available collections, inspect one collection, and fetch a specific record. Results are restricted to the fields and rows the connecting user may read.

Tools include collection discovery, record listing and retrieval, and action discovery. Write tools require both the appropriate scope and role. Actions can be held by [approval rules](/guides/actions).

## Understand the data boundary [#understand-the-data-boundary]

Record values returned to the MCP client may be sent to that client's model provider. Choose the client and provider according to your organization's requirements. Read [data flow](/administration/data-flow) for Aviato's own AI features, which are a separate flow.

## Debug a refused connection [#debug-a-refused-connection]

Check HTTPS reachability, the agent's public URL, workspace membership, and the scopes you granted. OAuth metadata is exposed at `/.well-known/oauth-protected-resource/mcp`. A client without compatible remote OAuth support may not complete the connection.
